CVE-2009-1912

Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
webspellwebspell
𝑥
≤ 4.2.0e
webspellwebspell
4.0
webspellwebspell
4.0.2c:c
webspellwebspell
4.1
webspellwebspell
4.01.00
webspellwebspell
4.1.1
webspellwebspell
4.01.01
webspellwebspell
4.01.02
webspellwebspell
4.1.2
webspellwebspell
4.2.0c:c
webspellwebspell
4.2.0d:d
𝑥
= Vulnerable software versions