Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php; and include and execute arbitrary local files via the (3) group parameter to upload.php.
References
Configurations
History
No history.
Information
Published : 2009-11-29 13:07
Updated : 2024-02-04 17:33
NVD link : CVE-2009-4088
Mitre link : CVE-2009-4088
CVE.ORG link : CVE-2009-4088
JSON object : View
Products Affected
telepark
- telepark.wiki
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')