PT-2009-5826 · Clear Content · Clear Content

Mizoz

·

Published

2009-10-02

·

Updated

2017-09-19

·

CVE-2009-3535

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Clear Content version 1.1
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the url parameter of the image.php file.
Recommendations For Clear Content version 1.1, consider restricting access to the image.php file until a patch is available, or apply configuration changes to prevent directory traversal attacks, such as validating and sanitizing the url parameter to prevent the inclusion of malicious input.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3535

Affected Products

Clear Content