Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

N0N0X

#39727of 53,634
6.8Total CVSS
Vulnerabilities · 1
PT-2011-2405
6.8
2011-01-20
Ax · Ax Developer Cms · CVE-2011-0506
**Name of the Vulnerable Software and Affected Versions** Ax Developer CMS (AxDCMS) version 0.1.1 **Description** The issue allows remote attackers to execute arbitrary code via a .. (dot dot) in the `aXconf[default language]` parameter in the modules/profile/user.php file. **Recommendations** For Ax Developer CMS (AxDCMS) version 0.1.1, avoid using the `aXconf[default language]` parameter in the affected modules/profile/user.php file until the issue is resolved.