Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Danny Moules

#51208of 53,633
4.3Total CVSS
Vulnerabilities · 1
PT-2009-2988
4.3
2009-01-29
Ninja · Ninja Blog · CVE-2009-0325
**Name of the Vulnerable Software and Affected Versions** Ninja Blog version 4.8 **Description** The issue allows remote attackers to read arbitrary files due to a directory traversal vulnerability in the entries/index.php file when magic quotes gpc is disabled. This is achieved by using a .. (dot dot) in the `cat` parameter. **Recommendations** For Ninja Blog version 4.8, consider disabling the `cat` parameter in the entries/index.php file until a patch is available, or enable magic quotes gpc to prevent the directory traversal vulnerability.