Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-6901
Description:Multiple directory traversal vulnerabilities in 2532designs 2532|Gigs 1.2.2 Stable, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) settings.php, (2) deleteuser.php, (3) mini_calendar.php, (4) manage_venues.php, and (5) manage_gigs.php, a different vector than CVE-2007-4585.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-6901
BugTraq ID: 32911
http://www.securityfocus.com/bid/32911
https://www.exploit-db.com/exploits/7510
http://secunia.com/advisories/26585
XForce ISS Database: 2532gigs-language-file-include(47465)
https://exchange.xforce.ibmcloud.com/vulnerabilities/47465




© 1998-2025 E-Soft Inc. All rights reserved.