Security Advisory

CVE-2009-1912

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-06-04 16:00:00
Last updated 2024-08-07 05:27:54
Assigner mitre
State PUBLISHED

Description

Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.