Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-2173

Remote file inclusion vulnerability

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Major
    • 1.4 M1
    • 1.3 RC1
    • {Unused} Core
    • None

    Description

      It's possible to include remote files using ?skin= in queries
      for example : http://skol.xwiki.org/xwiki/bin/view/Main/?skin=../mytest

      Attachments

        Activity

          People

            sdumitriu Sergiu Dumitriu
            raffaello Raffaello Pelagalli
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: