Vulnerability Description
PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter, a different vector than CVE-2008-4138.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Technote | Technote | 7.2 |
Related Weaknesses (CWE)
References
- http://osvdb.org/51740
- http://secunia.com/advisories/33732Vendor Advisory
- http://www.securityfocus.com/bid/33592Exploit
- https://www.exploit-db.com/exploits/7965
- http://osvdb.org/51740
- http://secunia.com/advisories/33732Vendor Advisory
- http://www.securityfocus.com/bid/33592Exploit
- https://www.exploit-db.com/exploits/7965
FAQ
What is CVE-2009-0441?
CVE-2009-0441 is a vulnerability with a CVSS score of 6.8 (MEDIUM). PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via ...
How severe is CVE-2009-0441?
CVE-2009-0441 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0441?
Check the references section above for vendor advisories and patch information. Affected products include: Technote Technote.