CVE-2009-1912
04.06.2009, 16:30
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.
Vendor | Product | Version |
---|---|---|
webspell | webspell | 𝑥 ≤ 4.2.0e |
webspell | webspell | 4.0 |
webspell | webspell | 4.0.2c:c |
webspell | webspell | 4.1 |
webspell | webspell | 4.01.00 |
webspell | webspell | 4.1.1 |
webspell | webspell | 4.01.01 |
webspell | webspell | 4.01.02 |
webspell | webspell | 4.1.2 |
webspell | webspell | 4.2.0c:c |
webspell | webspell | 4.2.0d:d |
𝑥
= Vulnerable software versions
References