CVE-2009-0592
16.02.2009, 17:30
Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ModName parameter to (1) admin_words.php, (2) admin_groups_reapir.php, (3) admin_smilies.php, (4) admin_ranks.php, (5) admin_styles.php, and (6) admin_users.php in admin/.
Vendor | Product | Version |
---|---|---|
pnphpbb | pnphpbb2 | 𝑥 ≤ 1.2i |
pnphpbb | pnphpbb2 | 1.0 |
pnphpbb | pnphpbb2 | 1.1 |
pnphpbb | pnphpbb2 | 1.1a:a |
pnphpbb | pnphpbb2 | 1.2 |
pnphpbb | pnphpbb2 | 1.2a:a |
pnphpbb | pnphpbb2 | 1.2d:d |
pnphpbb | pnphpbb2 | 1.2e:e |
pnphpbb | pnphpbb2 | 1.2f:f |
pnphpbb | pnphpbb2 | 1.2g:g |
pnphpbb | pnphpbb2 | 1.2h:h |
𝑥
= Vulnerable software versions