Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:02
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.jamroom.net/index.php?m=td_tracker&o=view&id=1470 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/34511 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/49869 - | |
References | () https://www.exploit-db.com/exploits/8423 - |
Information
Published : 2009-04-17 14:08
Updated : 2024-11-21 01:02
NVD link : CVE-2009-1318
Mitre link : CVE-2009-1318
CVE.ORG link : CVE-2009-1318
JSON object : View
Products Affected
jamroom
- jamroom
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')