CVE Database
/

CVE-2008-7054

Back to search

CVE-2008-7054

Published: Aug 24, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the (1) gsLanguage and (2) language_home parameters to modules/diary/showdiary.php; (3) admin_home, (4) gsLanguage, and (5) language_home parameters to modules/diary/showdiarydetail.php; (6) gsLanguage and (7) language_home parameters to modules/diary/submit_diary.php; (8) admin_home parameter to modules/news/news_summary.php; (9) nLink, (10) gsLanguage, and (11) language_home parameters to modules/news/inlinenews.php; and possibly other unspecified vectors in (12) diary/showeventlist.php, (13) gallery/showgallery.php, (14) reviews/showreviews.php, (15) gallery/showgallerydetails.php, (16) reviews/showreviewsdetails.php, (17) news/shownewsdetails.php, (18) gallery/submit_gallery.php, (19) guestbook/submit_guestbook.php, (20) reviews/submit_reviews.php, (21) news/submit_news.php, (22) diary/inlineeventlist.php, and (23) news/archivednews_summary.php in modules/, related to the lack of directory traversal protection in modules/moduleSec.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

47777
vdb-entry
x_refsource_OSVDB
47773
vdb-entry
x_refsource_OSVDB
6301
exploit
x_refsource_EXPLOIT-DB
31606
third-party-advisory
x_refsource_SECUNIA
47776
vdb-entry
x_refsource_OSVDB
47775
vdb-entry
x_refsource_OSVDB
30821
vdb-entry
x_refsource_BID
47774
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now