Description
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
Remediation
References
Related Vulnerabilities
WordPress Plugin Slimstat Analytics SQL Injection (5.0.4)
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3942)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4283)