LimeSurvey Remote File Include and Directory Traversal Vulnerabilities
10 Apr. 2012
Summary
LimeSurvey is prone to a remote file-include vulnerability and a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A successful exploit may allow an attacker to obtain sensitive information and execute malicious code within the context of the web server process. This may aid in further attacks.
Vendor Status:
Currently we are not aware of any vendor-supplied patches