CVE-2009-0340

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
29/01/2009
Last modified:
09/04/2025

Description

Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:quirm:simple_php_newsletter:1.5:*:*:*:*:*:*:*