CVE-2009-2444

EUVD-2009-2439
Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter to setup/index.php.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
adbnewssenderadbnewssender
𝑥
≤ 1.5.5
adbnewssenderadbnewssender
1.0
adbnewssenderadbnewssender
1.1
adbnewssenderadbnewssender
1.1.1
adbnewssenderadbnewssender
1.1.2
adbnewssenderadbnewssender
1.2.0
adbnewssenderadbnewssender
1.2.1
adbnewssenderadbnewssender
1.2.2
adbnewssenderadbnewssender
1.2.3
adbnewssenderadbnewssender
1.2.4
adbnewssenderadbnewssender
1.3.0
adbnewssenderadbnewssender
1.3.1
adbnewssenderadbnewssender
1.3.2
adbnewssenderadbnewssender
1.3.3
adbnewssenderadbnewssender
1.4.0
adbnewssenderadbnewssender
1.4.1
adbnewssenderadbnewssender
1.4.2
adbnewssenderadbnewssender
1.4.3
adbnewssenderadbnewssender
1.4.4
adbnewssenderadbnewssender
1.4.5
adbnewssenderadbnewssender
1.4.6
adbnewssenderadbnewssender
1.4.7
adbnewssenderadbnewssender
1.4.8
adbnewssenderadbnewssender
1.4.9
adbnewssenderadbnewssender
1.4.10
adbnewssenderadbnewssender
1.4.11
adbnewssenderadbnewssender
1.5.0
adbnewssenderadbnewssender
1.5.1
adbnewssenderadbnewssender
1.5.2
adbnewssenderadbnewssender
2.0:alpha1
adbnewssenderadbnewssender
2.0:alpha2
adbnewssenderadbnewssender
2.0:alpha3
adbnewssenderadbnewssender
2.0:alpha4
adbnewssenderadbnewssender
2.0:beta1
adbnewssenderadbnewssender
2.0:beta2
adbnewssenderadbnewssender
2.0:rc1
𝑥
= Vulnerable software versions