Required CVE Record Information
Description
Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- securityfocus.com: 29255 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: digitalhive-baseinclude-file-include(42495) vdb-entryx_transferred
- http://www.z0rlu.ownspace.org/index.php?/archives/85-hive-v2.0-RC2-LFi.html x_transferred