9.3
CVSSv2

CVE-2009-4216

Published: 07/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and previous versions allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the LANG parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

klinza klinza professional cms

Exploits

source: wwwsecurityfocuscom/bid/37127/info The 'klinza professional cms' project is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible This issue aff ...