CVE-2008-5962
23.01.2009, 19:00
Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the objectname parameter.
Vendor | Product | Version |
---|---|---|
gravity-gtd | gravity-gtd | 𝑥 ≤ 0.4.5 |
gravity-gtd | gravity-gtd | 0.2:beta |
gravity-gtd | gravity-gtd | 0.3 |
gravity-gtd | gravity-gtd | 0.4 |
𝑥
= Vulnerable software versions
References