CVE-2009-0645 Information

Description

Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language (2) Introduction_complete and (3) use_log parameters different vectors than CVE-2004-2445.

Reference

http://www.jaws-project.com/blog/show/jaws-089-released http://www.securityfocus.com/bid/33607 https://exchange.xforce.ibmcloud.com/vulnerabilities/48476 https://www.exploit-db.com/exploits/7976

Share on: