CVE-2009-2444
Published Jul 13, 2009
Last updated 7 years ago
Overview
- Description
- Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter to setup/index.php.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-22
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B412BB4-3E28-4678-9C3F-D2CB22D5E038", "versionEndIncluding": "1.5.5" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9F792DDE-D025-4F5B-AB1A-620A59900857" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A53D1A3-6A37-417B-8CF4-F5897635E774" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "815153B5-F97A-4C56-8C20-4F6E7C0D638A" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F051AB9-C299-4E9B-B4C2-EF77A0AE18E8" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C15AFACD-D8AD-415E-B050-7DAFC99506F2" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0CEF5136-210C-446B-9E32-6299B10CB69B" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D524626-B977-4356-A93F-88B435CFCA90" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "328B133E-7482-4946-BAB1-5D89C60041B1" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91A71223-CD88-446F-AF93-0626B39BE3EA" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80953021-E692-449B-A961-A369E8BB4A3C" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "683CA1FD-A4E4-41E4-97A1-01A77B520991" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1831F536-F07D-49E8-A863-FDAD8E383104" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD13616B-33A3-4E43-BB91-19E192FA67F6" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A250D35-B8DF-4999-997C-EC69AD725E36" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4A87D52-68B5-488E-BA5E-FDF61C798195" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8DDB844-AC56-443A-9099-DA0D54F070E0" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A8E8417-9BFE-4CB2-A218-458CD718F41B" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01092A5C-0F07-488B-9F02-ACCA96618BD2" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5AF12021-D316-4A18-B3E1-ED6AB9736EB9" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1758BFA0-47BA-49DB-8477-2996D6D03A72" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD0EEF2A-61CC-472C-BE91-7199318DA51B" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5CAD3C9-3D51-4DAA-930E-B9ECCDBAB6C7" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04F1B990-05DE-43FD-8923-CD2E675DE9F0" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0ECEF6BB-AF11-4427-B740-DC66AEA94DB7" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.4.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5B3BA36-997A-4CAF-9103-966881BDFC87" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E6AD1EB-77AD-4F2F-A604-C290274C9AB5" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04E5BC91-05F3-4E97-B47B-C0D4E620F22B" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:1.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AC95ACF-C82C-445F-AFB5-BE778EC3C3BF" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:2.0:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "244798D3-8486-43F7-9F90-CAB406564AF6" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:2.0:alpha2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "95A2C245-99A0-4DF2-B725-EB9F0E528E6E" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:2.0:alpha3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "228BE08C-4B63-4DE2-AFD3-C0B251F9C463" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:2.0:alpha4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4997E07-2357-4AD5-9CB6-E98D5D690A2C" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:2.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE0C0685-2380-441D-B1DB-0432B6E2ABE5" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:2.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB1FC7EA-E883-426F-AE5E-288BBFBEAEE2" }, { "criteria": "cpe:2.3:a:adbnewssender:adbnewssender:2.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3341B4AC-0A61-4437-8E8D-8D908C1CAE7C" } ], "operator": "OR" } ] } ]