Описание
Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter.
Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2010-1710
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57900
- http://packetstormsecurity.org/1004-exploits/siestta-lfixss.txt
- http://secunia.com/advisories/39453
- http://www.exploit-db.com/exploits/12260
- http://www.osvdb.org/63837
- http://www.securityfocus.com/bid/39526
Связанные уязвимости
nvd
почти 16 лет назад
Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter.