CVE-2009-2109
Last modified
CVE-2009-2109 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.. EPSS estimates a 9.48% chance of exploitation in the next 30 days.
Description
Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fretsweb Project | Fretsweb | 1.2 |
References
- http://osvdb.org/55166Broken Link
- http://osvdb.org/55196Broken Link
- http://secunia.com/advisories/35492Vendor Advisory
- https://www.exploit-db.com/exploits/8979Third Party Advisory, VDB Entry
- http://osvdb.org/55166Broken Link
- http://osvdb.org/55196Broken Link
- http://secunia.com/advisories/35492Vendor Advisory
- https://www.exploit-db.com/exploits/8979Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2109?
How severe is CVE-2009-2109?
How do I fix CVE-2009-2109?
Are you affected by CVE-2009-2109?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
