Back to Database
Status published
High
CVE-2009-4231
Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier...
Vulnerability Description
Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to include and execute arbitrary local files via .. (dot dot) in the plugin parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-4231
Credits & Attribution
No credits recorded in the NVD database.
More from basic-cms
View All →CVE-2011-3804
SweetRice 0.7.1 allows remote attackers to obtain sensitive information via...
Medium
5
CVE-2010-5318
The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1...
Medium
4.3
CVE-2010-5317
Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before...
High
7.5
CVE-2010-5316
Cross-site scripting (XSS) vulnerability in as/index.php in SweetRice CMS before...
Medium
4.3
CVE-2010-0695
Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote...
Medium
4.3
Affected Vendor
basic-cms
View all reports →Affected Software
sweetrice
Vulnerable Versions:
0, 0.2.0, 0.2.1, 0.3.0, 0.4.0, 0.4.1, 0.4.2, 0.4.4, 0.5.2
Timeline
Official Publish:
December 8th, 2009
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.