CVE-2014-3777
Directory traversal vulnerability in Reportico PHP Report Designer before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the xmlin parameter.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0021 (0.2%)
Percentile: 42.4%
EPSS: 2026-05-06
Affects
reportico:php_report_designerTechnical description
Directory traversal vulnerability in Reportico PHP Report Designer before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the xmlin parameter.
Published: 7/16/2014, 2:19:03 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://packetstormsecurity.com/files/127280/Reportico-Admin-Credential-Leak.html
- http://seclists.org/fulldisclosure/2014/Jun/144
- http://www.osvdb.org/108612
- http://www.secveritas.com/secv-05-1402.html
- http://packetstormsecurity.com/files/127280/Reportico-Admin-Credential-Leak.html
- http://seclists.org/fulldisclosure/2014/Jun/144
- http://www.osvdb.org/108612
- http://www.secveritas.com/secv-05-1402.html