CVE-2009-1912 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 3.2% (pctl 88)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 3.18% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-06-04 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| webspell | webspell |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | webSPELL 4.2.0e - 'page' Blind SQL Injection | 2009-05-07 |
References
- http://osvdb.org/54295
- http://secunia.com/advisories/35016
- http://www.osvdb.org/54296
- http://www.securityfocus.com/bid/34862
- http://www.webspell.org/
- http://www.webspell.org/index.php?site=files&file=30
- http://www.webspell.org/index.php?site=news_comments&newsID=130
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50395
- https://www.exploit-db.com/exploits/8622
- http://osvdb.org/54295
- http://secunia.com/advisories/35016
- http://www.osvdb.org/54296
- http://www.securityfocus.com/bid/34862
- http://www.webspell.org/
- http://www.webspell.org/index.php?site=files&file=30
- http://www.webspell.org/index.php?site=news_comments&newsID=130
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50395
- https://www.exploit-db.com/exploits/8622
→ the Explorer · watch your stack · NVD