RSS   Vulnerabilities for 'Lanai-core'   RSS

2010-07-28
 
CVE-2009-4961

CWE-200
 

 
Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.

 
 
CVE-2009-4960

CWE-22
 

 
Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top