4.3
CVSSv2

CVE-2008-6012

Published: 30/01/2009 Updated: 19/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in index.php in Pritlog 0.4 and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to read arbitrary files via a .. (dot dot) in the filename parameter in a viewEntry action.

Vulnerable Product Search on Vulmon Subscribe to Product

hardkap pritlog

hardkap pritlog 0.3

hardkap pritlog 0.2

Exploits

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= Printlog <= 04: Remote File Edition Vulnerability -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= $ Program: Printlog $ File affected: indexphp $ Version: 04 $ Download: wwwhardkapnet/pritlog Found by Pepelux <pepelux[at]enye-secorg> eNYe-Sec - wwwenye-secorg -- Descr ...