Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php; and include and execute arbitrary local files via the (3) group parameter to upload.php.
References
Configurations
Information
Published : 2009-11-29 05:07
Updated : 2017-08-16 18:31
NVD link : CVE-2009-4088
Mitre link : CVE-2009-4088
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
telepark
- telepark.wiki