phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://techdefencelabs.com/security-advisories.html | third party advisory |
https://www.phpmyfaq.de/security/advisory-2014-09-16 | vendor advisory |