CVE-2009-2180

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
23/06/2009
Last modified:
09/04/2025

Description

Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pc4arb:pc4_uploader:10.0:*:*:*:*:*:*:*