Vulnerability Details CVE-2009-1498
Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alpha SVN 243 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter in a settings action to profile.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.3%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2009-1498
-
Idb
»
Idb
»
Version: 0.2.5_pre-alpha
cpe:2.3:a:idb:idb:0.2.5_pre-alpha