CVE-2009-4512

Publication date

2009-12-31 19:00:00

Family

mitre

State

PUBLISHED

Description

Directory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URLs is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj_id parameter.