Appcanary is shutting down and joining GitHub. You can find out more here.
CVE-2009-2177
Metadata
CVE-2009-2177 | |
6.8 | |
securityfocus.com, exchange.xforce.ibmcloud.com, exploit-db.com | |
2009-06-23 | |
2017-09-29 06:09 |
Description
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (dot dot) in the s parameter, which is collapsed into a "../" value.