PT-2009-5037 · Unknown · School Data Navigator

Br0Ly

·

Published

2009-07-28

·

Updated

2017-09-19

·

CVE-2009-2641

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions School Data Navigator (affected versions not specified)
Description A remote file inclusion issue in the School Data Navigator allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. This can also be used to include and execute arbitrary local files using .. (dot dot) sequences.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2641

Affected Products

School Data Navigator