CVE-2009-4421
24.12.2009, 17:30
Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the blog_language1 parameter.
Vendor | Product | Version |
---|---|---|
alexander_palmo | simple_php_blog | 𝑥 ≤ 0.5.1 |
alexander_palmo | simple_php_blog | 0.3.7c:c |
alexander_palmo | simple_php_blog | 0.4.0 |
alexander_palmo | simple_php_blog | 0.4.5 |
alexander_palmo | simple_php_blog | 0.4.6 |
alexander_palmo | simple_php_blog | 0.4.7 |
alexander_palmo | simple_php_blog | 0.4.7.1 |
alexander_palmo | simple_php_blog | 0.5.0.1 |
𝑥
= Vulnerable software versions
References