peter bassill · operator
$ cve CVE-2009-0457 JSON

CVE-2009-0457 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 6.1% (pctl 93)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter to admin/case.php in the (1) Contact_Plus and (2) Reviews modules, and (3) the module_name parameter to admin/includes/FANCYNLOptions.php in the Fancy_NewsLetter module.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS6.11% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2009-02-10
Last modified2026-06-16

Affected (1)

VendorProduct
magtrbaja portal

Public exploits

SourceTitleDate
exploit-dbAJA Portal 1.2 (Windows) - Local File Inclusion2009-02-02

References

→ the Explorer  ·  watch your stack  ·  NVD