CVE-2009-1912: Path Traversal
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1912?
CVE-2009-1912 is considered a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary local .php files.
How do I fix CVE-2009-1912?
To fix CVE-2009-1912, users should upgrade to webSPELL version 4.2.0f or later where the vulnerability has been patched.
Which versions of webSPELL are affected by CVE-2009-1912?
CVE-2009-1912 affects webSPELL versions up to 4.2.0e, specifically versions 4.0, 4.1, and 4.2.0.
Can CVE-2009-1912 lead to SQL injection vulnerabilities?
Yes, CVE-2009-1912 can be leveraged for SQL injection by including specific files like awards.php.
What is the attack vector for CVE-2009-1912?
The attack vector for CVE-2009-1912 involves exploiting a directory traversal vulnerability through a specially crafted language cookie.