Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-1911


Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.


Published

2009-06-04T16:30:00.467

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tinywebgallery tinywebgallery ≤ 1.7.6 Yes
Application tinywebgallery tinywebgallery 1.0 Yes
Application tinywebgallery tinywebgallery 1.1 Yes
Application tinywebgallery tinywebgallery 1.01 Yes
Application tinywebgallery tinywebgallery 1.1.1 Yes
Application tinywebgallery tinywebgallery 1.1.2 Yes
Application tinywebgallery tinywebgallery 1.02 Yes
Application tinywebgallery tinywebgallery 1.2 Yes
Application tinywebgallery tinywebgallery 1.3 Yes
Application tinywebgallery tinywebgallery 1.03 Yes
Application tinywebgallery tinywebgallery 1.3a Yes
Application tinywebgallery tinywebgallery 1.3b Yes
Application tinywebgallery tinywebgallery 1.3c Yes
Application tinywebgallery tinywebgallery 1.04 Yes
Application tinywebgallery tinywebgallery 1.4 Yes
Application tinywebgallery tinywebgallery 1.4.0.1 Yes
Application tinywebgallery tinywebgallery 1.4.0.2 Yes
Application tinywebgallery tinywebgallery 1.4.0.3 Yes
Application tinywebgallery tinywebgallery 1.4.0.4 Yes
Application tinywebgallery tinywebgallery 1.4.1 Yes
Application tinywebgallery tinywebgallery 1.4.1.1 Yes
Application tinywebgallery tinywebgallery 1.4.1.2 Yes
Application tinywebgallery tinywebgallery 1.4.1.3 Yes
Application tinywebgallery tinywebgallery 1.4.2 Yes
Application tinywebgallery tinywebgallery 1.05 Yes
Application tinywebgallery tinywebgallery 1.5 Yes
Application tinywebgallery tinywebgallery 1.5.0.1_15.08.2006 Yes
Application tinywebgallery tinywebgallery 1.5.0.2_17.08.2006 Yes
Application tinywebgallery tinywebgallery 1.5.1_03.09.2006 Yes
Application tinywebgallery tinywebgallery 1.5.2.1_20.09.2006_1000 Yes
Application tinywebgallery tinywebgallery 1.5.2.2_21.09.2006_1000 Yes
Application tinywebgallery tinywebgallery 1.5.2_17.09.2006_1000 Yes
Application tinywebgallery tinywebgallery 1.5.3.1_11.10.2006_1000 Yes
Application tinywebgallery tinywebgallery 1.5.3.2_12.10.2006_1000 Yes
Application tinywebgallery tinywebgallery 1.5.3_08.10.2006_1000 Yes
Application tinywebgallery tinywebgallery 1.5.4_13.10.2006 Yes
Application tinywebgallery tinywebgallery 1.5.5_30.10.2006_2200 Yes
Application tinywebgallery tinywebgallery 1.6 Yes
Application tinywebgallery tinywebgallery 1.6.1 Yes
Application tinywebgallery tinywebgallery 1.6.2 Yes
Application tinywebgallery tinywebgallery 1.6.3 Yes
Application tinywebgallery tinywebgallery 1.6.3.4 Yes
Application tinywebgallery tinywebgallery 1.7 Yes
Application tinywebgallery tinywebgallery 1.7.1 Yes
Application tinywebgallery tinywebgallery 1.7.2-18.04.2008 Yes
Application tinywebgallery tinywebgallery 1.7.3-12.05.2008 Yes
Application tinywebgallery tinywebgallery 1.7.3.1 Yes
Application tinywebgallery tinywebgallery 1.7.3.2 Yes
Application tinywebgallery tinywebgallery 1.7.3.3 Yes
Application tinywebgallery tinywebgallery 1.7.4 Yes
Application tinywebgallery tinywebgallery 1.7.4.1 Yes
Application tinywebgallery tinywebgallery 1.7.4.2 Yes
Application tinywebgallery tinywebgallery 1.7.4.3 Yes
Application tinywebgallery tinywebgallery 1.7.4.4 Yes
Application tinywebgallery tinywebgallery 1.7.4.5 Yes
Application tinywebgallery tinywebgallery 1.7.5 Yes
Application tinywebgallery tinywebgallery 1.7.5.1 Yes
Application claudio_klingler quixplorer ≤ 2.3.2 Yes
Application claudio_klingler quixplorer 1.0 Yes
Application claudio_klingler quixplorer 1.1 Yes
Application claudio_klingler quixplorer 1.2 Yes
Application claudio_klingler quixplorer 1.4 Yes
Application claudio_klingler quixplorer 1.5 Yes
Application claudio_klingler quixplorer 1.6 Yes
Application claudio_klingler quixplorer 2.0 Yes
Application claudio_klingler quixplorer 2.1.1 Yes
Application claudio_klingler quixplorer 2.2 Yes
Application claudio_klingler quixplorer 2.3 Yes
Application claudio_klingler quixplorer 2.3.1 Yes

References