PT-2009-2988 · Ninja · Ninja Blog

Danny Moules

·

Published

2009-01-29

·

Updated

2024-02-14

·

CVE-2009-0325

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ninja Blog version 4.8
Description The issue allows remote attackers to read arbitrary files due to a directory traversal vulnerability in the entries/index.php file when magic quotes gpc is disabled. This is achieved by using a .. (dot dot) in the cat parameter.
Recommendations For Ninja Blog version 4.8, consider disabling the cat parameter in the entries/index.php file until a patch is available, or enable magic quotes gpc to prevent the directory traversal vulnerability.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2009-0325

Affected Products

Ninja Blog