CVE-2008-5962
23.01.2009, 19:00
Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the objectname parameter.
| Vendor | Product | Version |
|---|---|---|
| gravity-gtd | gravity-gtd | 𝑥 ≤ 0.4.5 |
| gravity-gtd | gravity-gtd | 0.2:beta |
| gravity-gtd | gravity-gtd | 0.3 |
| gravity-gtd | gravity-gtd | 0.4 |
𝑥
= Vulnerable software versions
References