CVE-2009-2184

Metadata

CVE-2009-2184
5.0
vupen.com, exchange.xforce.ibmcloud.com, exploit-db.com
2009-06-23
2017-09-29 06:09

Description

Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to read arbitrary files via an encoded "/" (slash) in the file parameter.

Related Vulnerabilities