CVE-2009-2444

Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter to setup/index.php.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
adbnewssenderadbnewssender
𝑥
≤ 1.5.5
adbnewssenderadbnewssender
1.0
adbnewssenderadbnewssender
1.1
adbnewssenderadbnewssender
1.1.1
adbnewssenderadbnewssender
1.1.2
adbnewssenderadbnewssender
1.2.0
adbnewssenderadbnewssender
1.2.1
adbnewssenderadbnewssender
1.2.2
adbnewssenderadbnewssender
1.2.3
adbnewssenderadbnewssender
1.2.4
adbnewssenderadbnewssender
1.3.0
adbnewssenderadbnewssender
1.3.1
adbnewssenderadbnewssender
1.3.2
adbnewssenderadbnewssender
1.3.3
adbnewssenderadbnewssender
1.4.0
adbnewssenderadbnewssender
1.4.1
adbnewssenderadbnewssender
1.4.2
adbnewssenderadbnewssender
1.4.3
adbnewssenderadbnewssender
1.4.4
adbnewssenderadbnewssender
1.4.5
adbnewssenderadbnewssender
1.4.6
adbnewssenderadbnewssender
1.4.7
adbnewssenderadbnewssender
1.4.8
adbnewssenderadbnewssender
1.4.9
adbnewssenderadbnewssender
1.4.10
adbnewssenderadbnewssender
1.4.11
adbnewssenderadbnewssender
1.5.0
adbnewssenderadbnewssender
1.5.1
adbnewssenderadbnewssender
1.5.2
adbnewssenderadbnewssender
2.0:alpha1
adbnewssenderadbnewssender
2.0:alpha2
adbnewssenderadbnewssender
2.0:alpha3
adbnewssenderadbnewssender
2.0:alpha4
adbnewssenderadbnewssender
2.0:beta1
adbnewssenderadbnewssender
2.0:beta2
adbnewssenderadbnewssender
2.0:rc1
𝑥
= Vulnerable software versions