CVE-2009-4960: Path Traversal
Published Jul 27, 2010
·Updated
Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
Affected Software
1 affected component
Lanai-core Lanai-core=0.6
Event History
Jul 27, 2010
CVE Published
via MITRE·06:39 PM
Data Sourced
via MITRE·06:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4960?
CVE-2009-4960 is classified as a medium severity vulnerability.
2
How do I fix CVE-2009-4960?
To fix CVE-2009-4960, update to a patched version of Lanai Core that resolves the directory traversal issue.
3
What application is affected by CVE-2009-4960?
CVE-2009-4960 affects Lanai Core version 0.6.
4
What type of vulnerability is CVE-2009-4960?
CVE-2009-4960 is a directory traversal vulnerability.
5
Can CVE-2009-4960 allow unauthorized file access?
Yes, CVE-2009-4960 can allow remote attackers to read arbitrary files on the server.