5
CVSSv2

CVE-2009-3912

Published: 09/11/2009 Updated: 09/11/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote malicious users to read arbitrary files via a ..%2F (encoded dot dot slash) in the album parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

tftgallery tftgallery 0.13

Exploits

Released information about the album parameter being vulnerable to XSS earlier Seems there are other similar issues: The album parameter is vulnerable to directory transversal examplecom/tftgallery/indexphp?album=%2F%2F%2F%2F%2F%2F%2F%2F%2F%2Fbootini%00&page=1<1921681130/tftgallery/indexphp?album= ...