Unrated severityNVD Advisory· Published Jan 29, 2009· Updated Apr 23, 2026
CVE-2009-0325
CVE-2009-0325
Description
Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.
Affected products
1- cpe:2.3:a:ninjadesigns:ninja_blog:4.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.securityfocus.com/bid/33351nvdExploit
- www.push55.co.uk/poclibrary/ninjadesignscouk-1.txtnvdExploitURL Repurposed
- secunia.com/advisories/33573nvdVendor Advisory
- www.push55.co.uk/index.phpnvdURL Repurposed
- www.exploit-db.com/exploits/7831nvd
News mentions
0No linked articles in our index yet.