6.8
CVE-2009-1911
- EPSS 9.91%
- Veröffentlicht 04.06.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tinywebgallery ≫ Tinywebgallery Version <= 1.7.6
Tinywebgallery ≫ Tinywebgallery Version1.0
Tinywebgallery ≫ Tinywebgallery Version1.1
Tinywebgallery ≫ Tinywebgallery Version1.01
Tinywebgallery ≫ Tinywebgallery Version1.1.1
Tinywebgallery ≫ Tinywebgallery Version1.1.2
Tinywebgallery ≫ Tinywebgallery Version1.02
Tinywebgallery ≫ Tinywebgallery Version1.2
Tinywebgallery ≫ Tinywebgallery Version1.3
Tinywebgallery ≫ Tinywebgallery Version1.03
Tinywebgallery ≫ Tinywebgallery Version1.3a
Tinywebgallery ≫ Tinywebgallery Version1.3b
Tinywebgallery ≫ Tinywebgallery Version1.3c
Tinywebgallery ≫ Tinywebgallery Version1.04
Tinywebgallery ≫ Tinywebgallery Version1.4
Tinywebgallery ≫ Tinywebgallery Version1.4.0.1
Tinywebgallery ≫ Tinywebgallery Version1.4.0.2
Tinywebgallery ≫ Tinywebgallery Version1.4.0.3
Tinywebgallery ≫ Tinywebgallery Version1.4.0.4
Tinywebgallery ≫ Tinywebgallery Version1.4.1
Tinywebgallery ≫ Tinywebgallery Version1.4.1.1
Tinywebgallery ≫ Tinywebgallery Version1.4.1.2
Tinywebgallery ≫ Tinywebgallery Version1.4.1.3
Tinywebgallery ≫ Tinywebgallery Version1.4.2
Tinywebgallery ≫ Tinywebgallery Version1.05
Tinywebgallery ≫ Tinywebgallery Version1.5
Tinywebgallery ≫ Tinywebgallery Version1.5.0.1_15.08.2006
Tinywebgallery ≫ Tinywebgallery Version1.5.0.2_17.08.2006
Tinywebgallery ≫ Tinywebgallery Version1.5.1_03.09.2006
Tinywebgallery ≫ Tinywebgallery Version1.5.2.1_20.09.2006_1000
Tinywebgallery ≫ Tinywebgallery Version1.5.2.2_21.09.2006_1000
Tinywebgallery ≫ Tinywebgallery Version1.5.2_17.09.2006_1000
Tinywebgallery ≫ Tinywebgallery Version1.5.3.1_11.10.2006_1000
Tinywebgallery ≫ Tinywebgallery Version1.5.3.2_12.10.2006_1000
Tinywebgallery ≫ Tinywebgallery Version1.5.3_08.10.2006_1000
Tinywebgallery ≫ Tinywebgallery Version1.5.4_13.10.2006
Tinywebgallery ≫ Tinywebgallery Version1.5.5_30.10.2006_2200
Tinywebgallery ≫ Tinywebgallery Version1.6
Tinywebgallery ≫ Tinywebgallery Version1.6.1
Tinywebgallery ≫ Tinywebgallery Version1.6.2
Tinywebgallery ≫ Tinywebgallery Version1.6.3
Tinywebgallery ≫ Tinywebgallery Version1.6.3.4
Tinywebgallery ≫ Tinywebgallery Version1.7
Tinywebgallery ≫ Tinywebgallery Version1.7.1
Tinywebgallery ≫ Tinywebgallery Version1.7.2-18.04.2008
Tinywebgallery ≫ Tinywebgallery Version1.7.3-12.05.2008
Tinywebgallery ≫ Tinywebgallery Version1.7.3.1
Tinywebgallery ≫ Tinywebgallery Version1.7.3.2
Tinywebgallery ≫ Tinywebgallery Version1.7.3.3
Tinywebgallery ≫ Tinywebgallery Version1.7.4
Tinywebgallery ≫ Tinywebgallery Version1.7.4.1
Tinywebgallery ≫ Tinywebgallery Version1.7.4.2
Tinywebgallery ≫ Tinywebgallery Version1.7.4.3
Tinywebgallery ≫ Tinywebgallery Version1.7.4.4
Tinywebgallery ≫ Tinywebgallery Version1.7.4.5
Tinywebgallery ≫ Tinywebgallery Version1.7.5
Tinywebgallery ≫ Tinywebgallery Version1.7.5.1
Claudio Klingler ≫ Quixplorer Version <= 2.3.2
Claudio Klingler ≫ Quixplorer Version1.0
Claudio Klingler ≫ Quixplorer Version1.1
Claudio Klingler ≫ Quixplorer Version1.2
Claudio Klingler ≫ Quixplorer Version1.4
Claudio Klingler ≫ Quixplorer Version1.5
Claudio Klingler ≫ Quixplorer Version1.6
Claudio Klingler ≫ Quixplorer Version2.0
Claudio Klingler ≫ Quixplorer Version2.1.1
Claudio Klingler ≫ Quixplorer Version2.2
Claudio Klingler ≫ Quixplorer Version2.3
Claudio Klingler ≫ Quixplorer Version2.3.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.91% | 0.928 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.