Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of these details are obtained from third party information. Vendor has supplied a patch for this vulnerability: http://cms.webspell.org/index.php?sitefiles&cat10
Publication date: Fri, 27 Jul 2007 00:30:00 +0000