Vulnerability Description
Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the pfadhier parameter. NOTE: some of these details are obtained from third party information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Papoo | Papoo | 3.6 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/33911Vendor Advisory
- http://www.securityfocus.com/bid/33718Exploit
- https://www.exploit-db.com/exploits/8030
- http://secunia.com/advisories/33911Vendor Advisory
- http://www.securityfocus.com/bid/33718Exploit
- https://www.exploit-db.com/exploits/8030
FAQ
What is CVE-2009-0735?
CVE-2009-0735 is a vulnerability with a CVSS score of 5.1 (MEDIUM). Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read and possibly exe...
How severe is CVE-2009-0735?
CVE-2009-0735 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0735?
Check the references section above for vendor advisories and patch information. Affected products include: Papoo Papoo.