Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the system parameter in modules/netshop/post.php; and the INCLUDE_FOLDER parameter in (2) auth.inc.php, (3) banner.inc.php, (4) blog.inc.php, and (5) forum.inc.php in modules/.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-12-26T17:08:00
Updated: 2024-08-07T11:04:44.535Z
Reserved: 2008-12-26T00:00:00
Link: CVE-2008-5728
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-12-26T17:30:00.657
Modified: 2024-11-21T00:54:45.393
Link: CVE-2008-5728
Redhat
No data.