CVE-2009-1911

UnknownEPSS 2.52%

Last modified

CVE-2009-1911 is a vulnerability of currently unknown severity. Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.. EPSS estimates a 2.52% chance of exploitation in the next 30 days.

Description

Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.

Metrics

EPSS Probability
2.52%

82.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TinywebgalleryTinywebgallery<= 1.7.6
TinywebgalleryTinywebgallery1.0
TinywebgalleryTinywebgallery1.1
TinywebgalleryTinywebgallery1.01
TinywebgalleryTinywebgallery1.1.1
TinywebgalleryTinywebgallery1.1.2
TinywebgalleryTinywebgallery1.02
TinywebgalleryTinywebgallery1.2
TinywebgalleryTinywebgallery1.3
TinywebgalleryTinywebgallery1.03
TinywebgalleryTinywebgallery1.3a
TinywebgalleryTinywebgallery1.3b
TinywebgalleryTinywebgallery1.3c
TinywebgalleryTinywebgallery1.04
TinywebgalleryTinywebgallery1.4
TinywebgalleryTinywebgallery1.4.0.1
TinywebgalleryTinywebgallery1.4.0.2
TinywebgalleryTinywebgallery1.4.0.3
TinywebgalleryTinywebgallery1.4.0.4
TinywebgalleryTinywebgallery1.4.1
TinywebgalleryTinywebgallery1.4.1.1
TinywebgalleryTinywebgallery1.4.1.2
TinywebgalleryTinywebgallery1.4.1.3
TinywebgalleryTinywebgallery1.4.2
TinywebgalleryTinywebgallery1.05
TinywebgalleryTinywebgallery1.5
TinywebgalleryTinywebgallery1.5.0.1_15.08.2006
TinywebgalleryTinywebgallery1.5.0.2_17.08.2006
TinywebgalleryTinywebgallery1.5.1_03.09.2006
TinywebgalleryTinywebgallery1.5.2.1_20.09.2006_1000
TinywebgalleryTinywebgallery1.5.2.2_21.09.2006_1000
TinywebgalleryTinywebgallery1.5.2_17.09.2006_1000
TinywebgalleryTinywebgallery1.5.3.1_11.10.2006_1000
TinywebgalleryTinywebgallery1.5.3.2_12.10.2006_1000
TinywebgalleryTinywebgallery1.5.3_08.10.2006_1000
TinywebgalleryTinywebgallery1.5.4_13.10.2006
TinywebgalleryTinywebgallery1.5.5_30.10.2006_2200
TinywebgalleryTinywebgallery1.6
TinywebgalleryTinywebgallery1.6.1
TinywebgalleryTinywebgallery1.6.2
TinywebgalleryTinywebgallery1.6.3
TinywebgalleryTinywebgallery1.6.3.4
TinywebgalleryTinywebgallery1.7
TinywebgalleryTinywebgallery1.7.1
TinywebgalleryTinywebgallery1.7.2-18.04.2008
TinywebgalleryTinywebgallery1.7.3-12.05.2008
TinywebgalleryTinywebgallery1.7.3.1
TinywebgalleryTinywebgallery1.7.3.2
TinywebgalleryTinywebgallery1.7.3.3
TinywebgalleryTinywebgallery1.7.4

Showing 50 of 69 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-1911?
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.
How severe is CVE-2009-1911?
Severity scoring for CVE-2009-1911 is pending analysis. The EPSS model estimates a 2.52% probability of exploitation in the next 30 days.
How do I fix CVE-2009-1911?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-1911?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST