CVE-2014-100029
Ganesha Digital Library - Path Traversal
Title source: ruleDescription
Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) newlang or (2) newtheme parameter.
Exploits (1)
Scores
EPSS
0.0717
EPSS Percentile
91.6%
Details
CWE
CWE-22
Status
published
Products (1)
ganesha_digital_library_project/ganesha_digital_library
4.2
Published
Jan 13, 2015
Tracked Since
Feb 18, 2026