Description
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
Remediation
References
Related Vulnerabilities
Joomla Other Vulnerability (CVE-2006-6833)
ATutor Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-12169)
WordPress Plugin Appointment Hour Booking-WordPress Booking Cross-Site Scripting (1.3.16)
Oracle Application Server CVE-2008-4017 Vulnerability (CVE-2008-4017)
WordPress Plugin Event Registration 'event_id' Parameter SQL Injection (5.32)