CVE-2009-0422
Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SERVER[ConfigFile] parameter to admin/index.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 6.20% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- tincan/phplist
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33533Vendor Advisory
- http://www.bugreport.ir/index_60.htmExploit
- http://www.securityfocus.com/archive/1/500057/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47945
- https://www.exploit-db.com/exploits/7778
- http://secunia.com/advisories/33533Vendor Advisory
- http://www.bugreport.ir/index_60.htmExploit
- http://www.securityfocus.com/archive/1/500057/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47945
- https://www.exploit-db.com/exploits/7778
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.