4
CVSSv2

CVE-2009-2116

Published: 18/06/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

skybluecanvas skybluecanvas 1.1

Exploits

source: wwwsecurityfocuscom/bid/44397/info SkyBlueCanvas is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input Exploiting this issue requires administrative privileges and may allow an attacker to obtain sensitive information that could aid in further attacks SkyBlueCanvas 11 r2 ...