Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "4.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.3"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.4"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.3"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.3"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.4"
},
{
"introduced": "0"
},
{
"last_affected": "4.2.5"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.3"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.5"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.6"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.7"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.8"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.9"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.10"
},
{
"introduced": "0"
},
{
"last_affected": "4.3.11"
},
{
"introduced": "0"
},
{
"last_affected": "4.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "4.4.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "4.4.0-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "4.4.0-rc2"
}
]
}