CVE-2010-4931: Path Traversal
DISPUTED Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folderlevel parameter. NOTE: this issue has been disputed by a reliable third party.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4931?
The severity of CVE-2010-4931 is disputed, with arguments surrounding the potential impact of the directory traversal vulnerability.
How do I fix CVE-2010-4931?
To fix CVE-2010-4931, ensure that all user inputs are properly sanitized and implement access controls to prevent unauthorized file inclusion.
Which systems are affected by CVE-2010-4931?
CVE-2010-4931 affects PHP-Fusion versions, allowing remote attackers to exploit the vulnerability through directory traversal.
What does the exploit for CVE-2010-4931 involve?
The exploit for CVE-2010-4931 involves using a .. (dot dot) in the folder_level parameter to include arbitrary local files.
Is CVE-2010-4931 actively being exploited?
As of the latest information, there is no confirmed active exploitation of CVE-2010-4931, but it remains a potential risk.