Lucene search

K
cve[email protected]CVE-2009-1318
HistoryApr 17, 2009 - 2:08 p.m.

CVE-2009-1318

2009-04-1714:08:52
CWE-22
web.nvd.nist.gov
19
cve
2009
1318
directory traversal
jamroom
nvd

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.2%

Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter.

Affected configurations

NVD
Node
jamroomjamroom
OR
jamroomjamroomMatch1.0
OR
jamroomjamroomMatch1.0b1
OR
jamroomjamroomMatch1.0b2
OR
jamroomjamroomMatch1.0b3
OR
jamroomjamroomMatch1.0b4
OR
jamroomjamroomMatch1.0b5
OR
jamroomjamroomMatch2.0.9
OR
jamroomjamroomMatch2.0.9a
OR
jamroomjamroomMatch2.6.10
OR
jamroomjamroomMatch2.6.11
OR
jamroomjamroomMatch2.6.12
OR
jamroomjamroomMatch2.60
OR
jamroomjamroomMatch2.60rc2
OR
jamroomjamroomMatch2.60rc3
OR
jamroomjamroomMatch2.61
OR
jamroomjamroomMatch2.62
OR
jamroomjamroomMatch2.63
OR
jamroomjamroomMatch2.64
OR
jamroomjamroomMatch2.65
OR
jamroomjamroomMatch2.66
OR
jamroomjamroomMatch2.67
OR
jamroomjamroomMatch2.68
OR
jamroomjamroomMatch2.69
OR
jamroomjamroomMatch3.0
OR
jamroomjamroomMatch3.0b1
OR
jamroomjamroomMatch3.0b2
OR
jamroomjamroomMatch3.0b3
OR
jamroomjamroomMatch3.0b4
OR
jamroomjamroomMatch3.0b5
OR
jamroomjamroomMatch3.0b6
OR
jamroomjamroomMatch3.0b7
OR
jamroomjamroomMatch3.0b8
OR
jamroomjamroomMatch3.0.1
OR
jamroomjamroomMatch3.0.2
OR
jamroomjamroomMatch3.0.3
OR
jamroomjamroomMatch3.0.4
OR
jamroomjamroomMatch3.0.5
OR
jamroomjamroomMatch3.0.6
OR
jamroomjamroomMatch3.0.7
OR
jamroomjamroomMatch3.0.8
OR
jamroomjamroomMatch3.0.9
OR
jamroomjamroomMatch3.0.10
OR
jamroomjamroomMatch3.0.11
OR
jamroomjamroomMatch3.0.12
OR
jamroomjamroomMatch3.0.13
OR
jamroomjamroomMatch3.0.14
OR
jamroomjamroomMatch3.0.15
OR
jamroomjamroomMatch3.0.16
OR
jamroomjamroomMatch3.0.17
OR
jamroomjamroomMatch3.0.18
OR
jamroomjamroomMatch3.0.19
OR
jamroomjamroomMatch3.0.20
OR
jamroomjamroomMatch3.0.21
OR
jamroomjamroomMatch3.0.22
OR
jamroomjamroomMatch3.0.23
OR
jamroomjamroomMatch3.0.24
OR
jamroomjamroomMatch3.0.25
OR
jamroomjamroomMatch3.0.26
OR
jamroomjamroomMatch3.0.27
OR
jamroomjamroomMatch3.0.28
OR
jamroomjamroomMatch3.0.29
OR
jamroomjamroomMatch3.0.30
OR
jamroomjamroomMatch3.1.0
OR
jamroomjamroomMatch3.1.0b1
OR
jamroomjamroomMatch3.1.0b2
OR
jamroomjamroomMatch3.1.0b3
OR
jamroomjamroomMatch3.1.1
OR
jamroomjamroomMatch3.1.2
OR
jamroomjamroomMatch3.1.3
OR
jamroomjamroomMatch3.1.4
OR
jamroomjamroomMatch3.1.5
OR
jamroomjamroomMatch3.2.0
OR
jamroomjamroomMatch3.2.1
OR
jamroomjamroomMatch3.2.2
OR
jamroomjamroomMatch3.2.3
OR
jamroomjamroomMatch3.2.4
OR
jamroomjamroomMatch3.2.5
OR
jamroomjamroomMatch3.2.6
OR
jamroomjamroomMatch3.3.0
OR
jamroomjamroomMatch3.3.1
OR
jamroomjamroomMatch3.3.2
OR
jamroomjamroomMatch3.3.3
OR
jamroomjamroomMatch3.3.4
OR
jamroomjamroomMatch3.3.5
OR
jamroomjamroomMatch3.3.6
OR
jamroomjamroomMatch3.3.7
OR
jamroomjamroomMatch3.3.8
OR
jamroomjamroomMatch4.0.2

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.2%

Related for CVE-2009-1318