CVE-2009-2081
16.06.2009, 19:30
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.
Vendor | Product | Version |
---|---|---|
phpwebthings | phpwebthings | 𝑥 ≤ 1.5.2 |
phpwebthings | phpwebthings | 0.1 |
phpwebthings | phpwebthings | 0.2 |
phpwebthings | phpwebthings | 0.2b:b |
phpwebthings | phpwebthings | 0.3 |
phpwebthings | phpwebthings | 0.4 |
phpwebthings | phpwebthings | 0.4.1 |
phpwebthings | phpwebthings | 0.4.2 |
phpwebthings | phpwebthings | 0.6.0 |
phpwebthings | phpwebthings | 1.0 |
phpwebthings | phpwebthings | 1.1a:a |
phpwebthings | phpwebthings | 1.4 |
phpwebthings | phpwebthings | 1.5.0 |
phpwebthings | phpwebthings | 1.5.1 |
𝑥
= Vulnerable software versions