Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-2611

EPSS 1.89% · P83
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-2611

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Directory traversal vulnerability in infusions/last_seen_users_panel/last_seen_users_panel.php in MyFusion (aka MyF) 6 Beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
MyFusion last_seen_users_panel.php目录遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
当register_globals被激活时,MyFusion (又称MyF)6 Beta(测试版)中的infusions/last_seen_users_panel/last_seen_users_panel.php中的目录遍历漏洞,允许远程攻击者借助settings[locale]参数中的".."放入和运行任意的本地文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-2611

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-2611

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-07-27 · 26 CVEs total

CVE-2008-6877Zen Cart 路径遍历漏洞
CVE-2009-2606Brainjar ASP Football Pool权限许可和信息泄露漏洞
CVE-2009-2605Traidnt Up 脚本adminquery.php SQL注入漏洞
CVE-2009-2604Zen Help Desk adminlogin.asp SQL注入漏洞
CVE-2009-2603Escon SupportPortal Pro index.php多个SQL注入漏洞
CVE-2009-2602R2 Newsletter权限许可和信息泄露漏洞
CVE-2009-2601Joomlaequipment SQL注入漏洞
CVE-2009-2600Akiva Webboard view.php目录遍历漏洞
CVE-2009-2599Radscripts RadCLASSIFIEDS Gold index.php SQL注入漏洞
CVE-2009-2598Online Grades & Attendance多个SQL注入漏洞
CVE-2009-2597Sun Java系统访问管理器Policy Agent拒绝服务漏洞
CVE-2009-2596Sun Solaris Auditing扩展文件属性本地拒绝服务漏洞
CVE-2008-6878Zen Cart 路径遍历漏洞
CVE-2009-2607Pinme com_pinboard SQL注入漏洞
CVE-2009-2619Datachecknh DataCheck Solutions V-SpacePal login.asp SQL注入漏洞
CVE-2009-2618Maxdev MDPro Survey模块'modules.php' SQL注入漏洞
CVE-2009-2617BaoFeng Storm 库medialib.dll 栈溢出漏洞
CVE-2009-2616Datachecknh DataCheck Solutions SitePal z_admin_login.asp SQL注入漏洞
CVE-2009-2615Datachecknh DataCheck Solutions SitePal多个跨站脚本攻击漏洞
CVE-2009-2614Datachecknh DataCheck Solutions LinkPal z_admin_login.asp SQL注入漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2009-2611

No comments yet


Leave a comment