Vulnerability Details CVE-2009-1678
Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the version parameter to boards/boards_rss.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2009-1678
-
cpe:2.3:a:bitweaver:bitweaver:-
-
cpe:2.3:a:bitweaver:bitweaver:1.1
-
cpe:2.3:a:bitweaver:bitweaver:1.1.1_beta
-
cpe:2.3:a:bitweaver:bitweaver:1.2.1
-
cpe:2.3:a:bitweaver:bitweaver:1.3
-
cpe:2.3:a:bitweaver:bitweaver:1.3.1
-
cpe:2.3:a:bitweaver:bitweaver:2.0.0
-
cpe:2.3:a:bitweaver:bitweaver:2.0.2
-
cpe:2.3:a:bitweaver:bitweaver:2.5