← Back

CVE-2009-1911

nvd nist
Published: Jun 4, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.

Affected (69)

Tinywebgallery
Quixplorer
Configuration A
57 vulnerable
Vulnerable SoftwareAffected Versions
Tinywebgallery
Up to 1.7.6
Version 1.01
Version 1.02
Version 1.03
Version 1.04
Version 1.05
Version 1.0
Version 1.1.1
Version 1.1.2
Version 1.1
Version 1.2
Version 1.3
Version 1.3a
Version 1.3b
Version 1.3c
Version 1.4.0.1
Version 1.4.0.2
Version 1.4.0.3
Version 1.4.0.4
Version 1.4.1.1
Version 1.4.1.2
Version 1.4.1.3
Version 1.4.1
Version 1.4.2
Version 1.4
Version 1.5.0.1_15.08.2006
Version 1.5.0.2_17.08.2006
Version 1.5.1_03.09.2006
Version 1.5.2.1_20.09.2006_1000
Version 1.5.2.2_21.09.2006_1000
Version 1.5.2_17.09.2006_1000
Version 1.5.3.1_11.10.2006_1000
Version 1.5.3.2_12.10.2006_1000
Version 1.5.3_08.10.2006_1000
Version 1.5.4_13.10.2006
Version 1.5.5_30.10.2006_2200
Version 1.5
Version 1.6.1
Version 1.6.2
Version 1.6.3.4
Version 1.6.3
Version 1.6
Version 1.7.1
Version 1.7.2-18.04.2008
Version 1.7.3-12.05.2008
Version 1.7.3.1
Version 1.7.3.2
Version 1.7.3.3
Version 1.7.4.1
Version 1.7.4.2
Version 1.7.4.3
Version 1.7.4.4
Version 1.7.4.5
Version 1.7.4
Version 1.7.5.1
Version 1.7.5
Version 1.7
Configuration B
12 vulnerable

References (14)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.