First published: Tue Jan 27 2009(Updated: )
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MAX_type parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open edX | =2.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0291 has a high severity due to the potential for remote code execution.
To fix CVE-2009-0291, upgrade OpenX to a version that is not vulnerable to directory traversal, such as 2.6.4 or later.
CVE-2009-0291 affects OpenX version 2.6.3.
Yes, CVE-2009-0291 allows remote attackers to include and execute arbitrary files on the server.
CVE-2009-0291 is known to have been exploited in the wild, making it a notable vulnerability.