Vulnerability Details CVE-2009-3694
Directory traversal vulnerability in config/config.php in ezRecipe-Zee 91, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg[prePath] parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.2%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2009-3694
-
cpe:2.3:a:jdtmmsm:ezrecipe-zee:91