Summary
Detail | |||
---|---|---|---|
Vendor | Allisclear | First view | 2009-10-02 |
Product | Clear Content | Last view | 2009-10-02 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:a:allisclear:clear_content:1.1:*:*:*:*:*:*:* | 2 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
7.5 | 2009-10-02 | CVE-2009-3538 | Directory traversal vulnerability in thumb.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |
4.3 | 2009-10-02 | CVE-2009-3535 | Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the researcher also suggests an analogous PHP remote file inclusion vulnerability, but this may be incorrect. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (2) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
55743 | Clear Content thumb.php url Parameter Traversal Local File Inclusion |
55742 | Clear Content image.php url Parameter Traversal Local File Inclusion |