PT-2009-4562 · Unknown · Db Top Sites

Sirgod

·

Published

2009-06-18

·

Updated

2017-09-29

·

CVE-2009-2110

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DB Top Sites version 1.0
Description The issue allows remote attackers to include and execute arbitrary local files due to multiple directory traversal vulnerabilities. This is possible when magic quotes gpc is disabled, and a .. (dot dot) is used in the u parameter to API endpoints such as "full.php", "index.php", and "contact.php".
Recommendations For DB Top Sites version 1.0, consider disabling the execution of files through the "full.php", "index.php", and "contact.php" API endpoints until a fix is available, and ensure magic quotes gpc is enabled to prevent directory traversal attacks.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2110

Affected Products

Db Top Sites