CVE-2008-5948
EUVD-2008-591823.01.2009, 19:00
Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bncwi | bncwi | 𝑥 ≤ 1.04 |
| bncwi | bncwi | 1.03 |
𝑥
= Vulnerable software versions