Arbitrary File Read Vulnerability in DamiCMS 6.0.1

Arbitrary File Read Vulnerability in DamiCMS 6.0.1

CVE-2018-20571 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file.

Learn more about our Cms Pen Testing.