CVE-2011-1715
MEDIUM 5.0EPSS 8.9%
Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to read arbitrary files via ..%2f (encoded dot dot) sequences in the file parameter.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 8.88% chance of exploitation in the next 30 days, 95th percentile
- Published
- 2011-04-18
- Updated
- 2024-08-06