CVE-2011-5219

Mpdf < 5.3 - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

Exploits (1)

exploitdb WORKING POC
by ZadYree · perlwebappsphp
https://www.exploit-db.com/exploits/18248

Scores

EPSS 0.1519
EPSS Percentile 94.6%

Details

CWE
CWE-22
Status published
Products (2)
mpdf1/mpdf 5.2
mpdf1/mpdf < 5.3
Published Oct 25, 2012
Tracked Since Feb 18, 2026