RSS   Vulnerabilities for 'Keep it simple guest book'   RSS

2008-04-02
 
CVE-2008-1635

CWE-22
 

 
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected.

 


Copyright 2024, cxsecurity.com

 

Back to Top