Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters.
References
Configurations
History
21 Nov 2024, 01:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/68062 - | |
References | () http://pridels-team.blogspot.com/2010/09/netartmedia-real-estate-portal-v20-xss.html - | |
References | () http://secunia.com/advisories/41377 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/43266 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/61867 - |
Information
Published : 2010-09-24 21:00
Updated : 2025-04-11 00:51
NVD link : CVE-2010-3606
Mitre link : CVE-2010-3606
CVE.ORG link : CVE-2010-3606
JSON object : View
Products Affected
netartmedia
- real_estate_portal
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')