Loading...
Loading...
Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the currentpath parameter, in conjunction with certain ... (triple dot) and ..... sequences in the currentfile parameter, to index.php.
June 30, 2008
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-2913
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.