CVE Database
/

CVE-2009-2333

Back to search

CVE-2009-2333

Published: Jul 5, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the menu parameter to admin/admin_menu.php, and the id parameter to (2) index.php and (3) admin/admin_edit.php; and (4) delete arbitrary local files via a .. (dot dot) in the id parameter to admin/admin_delete.php. NOTE: vector 2 can be leveraged for static code injection by sending a crafted menu parameter to admin/admin_menu.php, and then sending an id=../menu.csv request to index.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

55666
vdb-entry
x_refsource_OSVDB
9069
exploit
x_refsource_EXPLOIT-DB
55668
vdb-entry
x_refsource_OSVDB
55669
vdb-entry
x_refsource_OSVDB
55667
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now