6.8
CVSSv2

CVE-2009-0340

Published: 29/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote malicious users to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.

Vulnerable Product Search on Vulmon Subscribe to Product

quirm simple php newsletter 1.5

Exploits

--:local file include:-- --------------------------------- script:Simple PHP Newsletter 15 ---------------------------------------------- download from:quirmnet/download/23/ ---------------------------------------------- vul:/mailphp line 11: if ...