CVE-2009-4426
Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the blog parameter to (1) comment.php and (2) view.php.
- Affected products
- Ignition
- Launchpad Ignition
- = 1.2
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 2.3% (82th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2009-12-28
CVE-2009-4426 at NVD
1 known exploit for CVE-2009-4426
Proof-of-concept code and exploit modules indexed by Sploitus