Unrated severityNVD Advisory· Published Jul 8, 2009· Updated Apr 23, 2026
CVE-2009-2379
CVE-2009-2379
Description
Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
Affected products
1- cpe:2.3:a:bigace:bigace_cms:2.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- forum.bigace.de/announcements/security-patch-for-bigace-2-6nvdPatch
- www.bigace.de/Security-patch-for-BIGACE-2.6-released.htmlnvdPatchVendor Advisory
- securitytracker.com/idnvdExploit
- www.securityfocus.com/bid/35537nvdExploit
- secunia.com/advisories/35643nvdVendor Advisory
- osvdb.org/55510nvd
- www.exploit-db.com/exploits/9052nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/51444nvd
News mentions
0No linked articles in our index yet.