CVE-2009-1678
18.05.2009, 18:30
Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the version parameter to boards/boards_rss.php.
Vendor | Product | Version |
---|---|---|
bitweaver | bitweaver | 𝑥 ≤ 2.6 |
bitweaver | bitweaver | 1.1 |
bitweaver | bitweaver | 1.1.1_beta:_beta |
bitweaver | bitweaver | 1.2.1 |
bitweaver | bitweaver | 1.3 |
bitweaver | bitweaver | 1.3.1 |
bitweaver | bitweaver | 2.0.0 |
bitweaver | bitweaver | 2.0.2 |
bitweaver | bitweaver | 2.5 |
𝑥
= Vulnerable software versions
References