CVE-2008-5989
28.01.2009, 15:30
Directory traversal vulnerability in defs.php in PHPcounter 1.3.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.
Vendor | Product | Version |
---|---|---|
phpcounter | phpcounter | 𝑥 ≤ 1.3.2 |
phpcounter | phpcounter | 1.2.0 |
phpcounter | phpcounter | 1.2.1 |
phpcounter | phpcounter | 1.2.2 |
phpcounter | phpcounter | 1.2.3 |
phpcounter | phpcounter | 1.2.4 |
phpcounter | phpcounter | 1.2.5 |
phpcounter | phpcounter | 1.2.6 |
phpcounter | phpcounter | 1.2.7 |
phpcounter | phpcounter | 1.3.0 |
phpcounter | phpcounter | 1.3.1 |
𝑥
= Vulnerable software versions
References