High severity7.5NVD Advisory· Published Jun 4, 2017· Updated May 13, 2026
CVE-2017-9428
CVE-2017-9428
Description
A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via ..\ sequences in the directory parameter.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/bigtreecms/BigTree-CMS/issues/289nvdExploitIssue TrackingPatch
News mentions
0No linked articles in our index yet.