CVE-2020-35284
Published Dec 26, 2020Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; howeve…
Vendor archive
1 CVEs tagged to vendor flamingoim_project — 0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; howeve…