7.8
CVSSv2

CVE-2009-2925

Published: 21/08/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote malicious users to read arbitrary files via a .. (dot dot) in the TEMPLATE parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

djcalendar djcalendar -

Exploits

Discovered by cibbao PoC: /cgi-bin/DJcalendarcgi?TEMPLATE=////////etc/passwd # milw0rmcom [2009-07-14] ...