CVE-2008-2969
Yektaweb Academic Web Tools < 1.4.2.8 - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in download.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the dfile parameter.
Exploits (1)
References (5)
Scores
EPSS
0.0263
EPSS Percentile
85.7%
Details
CWE
CWE-22
Status
published
Products (2)
yektaweb/academic_web_tools
1.4.3.1
yektaweb/academic_web_tools
< 1.4.2.8
Published
Jul 02, 2008
Tracked Since
Feb 18, 2026