CVE-2009-1765 Information
Feb 14, 2021
cve
Description
Multiple directory traversal vulnerabilities in pluck 4.6.2 when register_globals is enabled allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref parameter to (1) data/modules/contactform/module_info.php (2) data/modules/blog/module_info.php and (3) data/modules/albums/module_info.php different vectors than CVE-2008-3194.
Reference
http://secunia.com/advisories/35145 http://www.securityfocus.com/bid/35007 https://www.exploit-db.com/exploits/8715
Share on: