Explore Vulnerabilities SQL Injection Cross-Site Scripting (XSS) Buffer Overflow Denial of Service Remote Code Execution Remote File Include Directory Traversal HTML Injection Stack Overflow Authentication Bypass
by: Al Baradi Joy vendor: YesWiki Show More YesWiki Unauthenticated Path Traversal YesWiki before 4.5.2 allows unauthenticated path traversal via the 'squelette' parameter. An attacker can exploit this to read arbitrary files on the server, like /etc/passwd. 7.1 CVSS HIGH Unauthenticated Path Traversal (LFI) 22 CWE Product Name YesWiki Platforms Tested Ubuntu 22.04 Affected Version From: < 4.5.2 To: 4.5.2001 2025