Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.
References
Link | Resource |
---|---|
http://osvdb.org/55166 | Broken Link |
http://osvdb.org/55196 | Broken Link |
http://secunia.com/advisories/35492 | Vendor Advisory |
https://www.exploit-db.com/exploits/8979 | Third Party Advisory VDB Entry |
http://osvdb.org/55166 | Broken Link |
http://osvdb.org/55196 | Broken Link |
http://secunia.com/advisories/35492 | Vendor Advisory |
https://www.exploit-db.com/exploits/8979 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 01:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/55166 - Broken Link | |
References | () http://osvdb.org/55196 - Broken Link | |
References | () http://secunia.com/advisories/35492 - Vendor Advisory | |
References | () https://www.exploit-db.com/exploits/8979 - Third Party Advisory, VDB Entry |
31 Aug 2023, 16:17
Type | Values Removed | Values Added |
---|---|---|
References | (OSVDB) http://osvdb.org/55166 - Broken Link | |
References | (OSVDB) http://osvdb.org/55196 - Broken Link | |
References | (EXPLOIT-DB) https://www.exploit-db.com/exploits/8979 - Third Party Advisory, VDB Entry | |
First Time |
Fretsweb Project
Fretsweb Project fretsweb |
|
CPE | cpe:2.3:a:fretsweb_project:fretsweb:1.2:*:*:*:*:*:*:* |
Information
Published : 2009-06-18 21:30
Updated : 2024-11-21 01:04
NVD link : CVE-2009-2109
Mitre link : CVE-2009-2109
CVE.ORG link : CVE-2009-2109
JSON object : View
Products Affected
fretsweb_project
- fretsweb
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')