lote27 (All Versions) - Arbitrary File Download
highThe lote27 theme for WordPress is vulnerable to Arbitrary File Download via the 'download' parameter found in the 'download.php' file. This makes it possible for unauthenticated attackers to download any file from the server which may contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Jan 9, 2014