CVE-2009-4088

Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php; and include and execute arbitrary local files via the (3) group parameter to upload.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:telepark:telepark.wiki:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:08

Type Values Removed Values Added
References () http://blog.telepark.com/telepark-web-software/2009/11/09/telepark-wiki-security-fixes/ - Patch () http://blog.telepark.com/telepark-web-software/2009/11/09/telepark-wiki-security-fixes/ - Patch
References () http://packetstormsecurity.org/0911-exploits/Telepark-fixes-nov09-2.txt - Exploit () http://packetstormsecurity.org/0911-exploits/Telepark-fixes-nov09-2.txt - Exploit
References () http://secunia.com/advisories/37391 - Vendor Advisory () http://secunia.com/advisories/37391 - Vendor Advisory
References () http://www.exploit-db.com/exploits/9483 - () http://www.exploit-db.com/exploits/9483 -
References () http://www.osvdb.org/60216 - () http://www.osvdb.org/60216 -
References () http://www.osvdb.org/60217 - () http://www.osvdb.org/60217 -
References () http://www.osvdb.org/60218 - () http://www.osvdb.org/60218 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/54327 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/54327 -

Information

Published : 2009-11-29 13:07

Updated : 2024-11-21 01:08


NVD link : CVE-2009-4088

Mitre link : CVE-2009-4088

CVE.ORG link : CVE-2009-4088


JSON object : View

Products Affected

telepark

  • telepark.wiki
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')