Description
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the gnew_language cookie.
Exploits (1)
References (3)
Core 3
Core References
Exploit x_refsource_misc
http://packetstormsecurity.com/files/123482
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/28684
Exploit x_refsource_misc
https://www.htbridge.com/advisory/HTB23171
Scores
EPSS
0.0459
EPSS Percentile
89.3%
Details
CWE
CWE-22
Status
published
Products (1)
raoul_proenca/gnew
< 2013.1
Published
Mar 11, 2014
Tracked Since
Feb 18, 2026