Directory Traversal Vulnerability in Horizon Quick Content Management System by Horizon
CVE-2013-7138
Currently unrated
Key Information:
- Vendor
- CVE Published:
- 9 January 2014
What is CVE-2013-7138?
The Horizon Quick Content Management System (QCMS) versions 4.0 and earlier are susceptible to a directory traversal vulnerability located in the file lib/functions/d-load.php. This flaw permits remote attackers to gain unauthorized access to arbitrary files on the server by manipulating the 'start' parameter to include directory traversal sequences. Consequently, this can lead to the exposure of sensitive information, thereby posing a significant security risk to the affected systems.
