CVE-2009-0535: Path Traversal
Published Feb 11, 2009
·Updated
Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when registerglobals is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the exportto parameter.
Affected Software
1 affected component
Extrosoft Thyme=1.3
Event History
Feb 11, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0535?
The severity of CVE-2009-0535 is rated as high, with a score of 7.5.
2
What is the impact of CVE-2009-0535?
CVE-2009-0535 allows remote attackers to read arbitrary files on the server due to a directory traversal vulnerability.
3
How do I fix CVE-2009-0535?
To fix CVE-2009-0535, ensure that register_globals is disabled and update to a patched version of Extrosoft Thyme if available.
4
What products are affected by CVE-2009-0535?
CVE-2009-0535 affects Extrosoft Thyme versions 1.3 and earlier.
5
How does CVE-2009-0535 exploit target systems?
CVE-2009-0535 exploits target systems by allowing attackers to use the '..' (dot dot) in the export_to parameter to navigate the file system.