Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cwd@Rbe

#39932of 53,635
6.8Total CVSS
Vulnerabilities · 1
PT-2009-4807
6.8
2009-07-08
Bigace · Bigace Web Cms · CVE-2009-2379
**Name of the Vulnerable Software and Affected Versions** BIGACE Web CMS version 2.6 **Description** A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the `cmd` parameter. **Recommendations** For BIGACE Web CMS version 2.6, consider restricting access to the `cmd` parameter in the public/index.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the `cmd` parameter with untrusted input until a patch is available.