Security Advisory

CVE-2009-2641

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-07-28 19:06:00
Last updated 2024-08-07 05:59:56
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.