PT-2009-5527 · Vivaprograms · Vivaprograms Infinity Script
Published
2009-09-16
·
Updated
2017-08-17
·
CVE-2009-3211
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
VivaPrograms Infinity Script versions 2.x.x
Description
The issue allows remote attackers to read arbitrary files due to a directory traversal vulnerability. This occurs when the
magic quotes gpc setting is disabled and a .. (dot dot) sequence is used in the options[style dir] parameter.Recommendations
For VivaPrograms Infinity Script versions 2.x.x, consider disabling the
options[style dir] parameter or restricting its use until a patch is available. Additionally, enabling magic quotes gpc may help mitigate the issue.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vivaprograms Infinity Script