PT-2009-1676 · Kwsphp · Kwsphp

Ajax

+1

·

Published

2009-02-20

·

Updated

2017-10-19

·

CVE-2008-6201

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KwsPHP version 1.3.456
Description A directory traversal issue in the eskuel module's help.php file allows remote attackers to execute arbitrary commands by manipulating the action parameter.
Recommendations For version 1.3.456, consider restricting access to the action parameter in the help.php file of the eskuel module to prevent command execution until a fix is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6201

Affected Products

Kwsphp