Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder_level parameter. NOTE: this issue has been disputed by a reliable third party
References
Link | Resource |
---|---|
http://attrition.org/pipermail/vim/2010-August/002391.html | Exploit Third Party Advisory |
http://www.exploit-db.com/exploits/14647 | Exploit Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/42456 | Exploit Third Party Advisory VDB Entry |
http://attrition.org/pipermail/vim/2010-August/002391.html | Exploit Third Party Advisory |
http://www.exploit-db.com/exploits/14647 | Exploit Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/42456 | Exploit Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 01:22
Type | Values Removed | Values Added |
---|---|---|
References | () http://attrition.org/pipermail/vim/2010-August/002391.html - Exploit, Third Party Advisory | |
References | () http://www.exploit-db.com/exploits/14647 - Exploit, Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/42456 - Exploit, Third Party Advisory, VDB Entry |
07 Nov 2023, 02:06
Type | Values Removed | Values Added |
---|---|---|
Summary | Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder_level parameter. NOTE: this issue has been disputed by a reliable third party |
Information
Published : 2011-10-09 10:55
Updated : 2024-11-21 01:22
NVD link : CVE-2010-4931
Mitre link : CVE-2010-4931
CVE.ORG link : CVE-2010-4931
JSON object : View
Products Affected
php-fusion
- php-fusion
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')