PT-2009-5273 · Bitmixsoft · Php-Lance

Jetli007

·

Published

2009-08-21

·

Updated

2017-09-19

·

CVE-2009-2923

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: BitmixSoft PHP-Lance version 1.52
Description: The issue allows remote attackers to read arbitrary files due to multiple directory traversal vulnerabilities. This can be achieved by including a .. (dot dot) in the language parameter to "show.php" and in the parameter to "advanced search.php".
Recommendations: For version 1.52, consider restricting access to the "show.php" and "advanced search.php" scripts until a patch is available. As a temporary workaround, avoid using the language parameter in the "show.php" script and restrict the use of parameters in "advanced search.php" to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2923

Affected Products

Php-Lance