6.8
CVSSv2

CVE-2009-4435

Published: 28/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in F3Site 2009 allow remote malicious users to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[nlang] parameter to (1) mod/poll.php and (2) mod/new.php.

Vulnerable Product Search on Vulmon Subscribe to Product

compmaster.prv.pl f3site 2009

Exploits

source: wwwsecurityfocuscom/bid/37408/info F3Site is prone to multiple local file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible F3Site 2009 is vulnerable; other v ...
source: wwwsecurityfocuscom/bid/37408/info F3Site is prone to multiple local file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible F3Site 2009 is vulnerable; othe ...