CVE-2009-1319

Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the lang parameter to index.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:guestcal:guest_cal:2.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-04-17 14:08

Updated : 2025-04-09 00:30


NVD link : CVE-2009-1319

Mitre link : CVE-2009-1319

CVE.ORG link : CVE-2009-1319


JSON object : View

Products Affected

guestcal

  • guest_cal
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')