Description
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Cross-Site Scripting (3.0.0 - 3.9.26)
WordPress Plugin Asgaros Forum Cross-Site Request Forgery (1.5.8)
Joomla! Core Security Bypass (2.5.0 - 3.8.7)
WordPress Plugin Broken Link Checker PHAR Deserialization (1.11.16)
WordPress Plugin Flip Book 'php.php' Arbitrary File Upload (1.0)