CVE-2009-2166: Path Traversal
Published Jun 22, 2009
·Updated
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
Affected Software
12 affected components
Ocsinventory-ng Ocs Inventory Ng<=1.02
Ocsinventory-ng Ocs Inventory Ng=1.0
Ocsinventory-ng Ocs Inventory Ng=1.0-beta
Ocsinventory-ng Ocs Inventory Ng=1.0-rc1
Ocsinventory-ng Ocs Inventory Ng=1.0-rc2
Ocsinventory-ng Ocs Inventory Ng=1.0-rc3
Ocsinventory-ng Ocs Inventory Ng=1.0-rc3-1
Ocsinventory-ng Ocs Inventory Ng=1.01
Ocsinventory-ng Ocs Inventory Ng=1.02-rc1
Ocsinventory-ng Ocs Inventory Ng=1.02-rc2
Ocsinventory-ng Ocs Inventory Ng=1.02-rc3
Unix Unix
Event History
Jun 22, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
08:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-2166?
CVE-2009-2166 is classified as a high severity vulnerability due to its ability to allow remote attackers to read arbitrary files.
2
How do I fix CVE-2009-2166?
To fix CVE-2009-2166, upgrade OCS Inventory NG to version 1.02.1 or later.
3
Which versions of OCS Inventory NG are affected by CVE-2009-2166?
OCS Inventory NG versions prior to 1.02.1, including 1.0, 1.01, and all beta and release candidate versions are affected.
4
What type of vulnerability is CVE-2009-2166?
CVE-2009-2166 is an absolute path traversal vulnerability that allows unauthorized file access on the server.
5
Can CVE-2009-2166 be exploited remotely?
Yes, CVE-2009-2166 can be exploited remotely by attackers who can manipulate the log parameter.