Back to Database
Status published
Medium
CVE-2009-0340
Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow...
Vulnerability Description
Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-0340
Credits & Attribution
No credits recorded in the NVD database.
References
More from quirm
View All →CVE-2011-3854
Cross-site scripting (XSS) vulnerability in the ZenLite theme before 4.4...
Medium
4.3
CVE-2009-0331
Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery...
High
7.8
CVE-2007-4863
SQL injection vulnerability in example.php in SAXON 5.4 allows remote...
Medium
6.8
CVE-2007-4862
Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows...
Medium
4.3
CVE-2007-4861
SAXON 5.4, with display_errors enabled, allows remote attackers to obtain...
Medium
5
Affected Vendor
quirm
View all reports →Affected Software
simple php newsletter
Vulnerable Versions:
1.5
Timeline
Official Publish:
January 29th, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.