5
CVSSv2

CVE-2009-4434

Published: 28/12/2009 Updated: 29/12/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the include_file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

idevspot isupport

idevspot isupport 1.06

idevspot isupport 1.02

Exploits

--------------------------------------------- ++ iSupport <= 18 ++ XSS/Local File Include Exploit --------------------------------------------- Discovered by : Stink' & Essandre DATE : 16/12/09 ////////////////////////////////////////////////////////////////////// Website : wwwidevspotcom/ DEMO : wwwidevspotcom/demo/iS ...