Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Cwd@Rbe

#40380de 53,638
6.8CVSS total
Vulnerabilidades · 1
PT-2009-4807
6.8
2009-07-08
Bigace · Bigace Web Cms · CVE-2009-2379
**Name of the Vulnerable Software and Affected Versions** BIGACE Web CMS version 2.6 **Description** A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the `cmd` parameter. **Recommendations** For BIGACE Web CMS version 2.6, consider restricting access to the `cmd` parameter in the public/index.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the `cmd` parameter with untrusted input until a patch is available.