VYPR
High severity7.5NVD Advisory· Published Dec 11, 2018· Updated Jun 17, 2026

CVE-2018-20064

CVE-2018-20064

Description

doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&action=edit&name=doorgets&file=../../1.txt%00 URI with content in the theme_content_nofi parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Doorgets/Doorgetsinferred3 versions
    = 7.0+ 2 more
    • (no CPE)range: = 7.0
    • cpe:2.3:a:doorgets:doorgets:7.0:*:*:*:*:*:*:*
    • (no CPE)range: <7.0
  • Doorgets/CMSllm-create
    Range: <7.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.