RSS   Vulnerabilities for 'Webframe'   RSS

2009-02-10
 
CVE-2009-0514

CWE-22
 

 
Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) currentmod and (2) LANG parameters to mod/index.php.

 
 
CVE-2009-0513

CWE-94
 

 
Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles parameter to (1) admin/doc/index.php, (2) index.php, and (3) base/menu.php in mod/.

 


Copyright 2024, cxsecurity.com

 

Back to Top