CVE-2009-0515

YANOCC <0.1.0 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Kacper · textwebappsphp
https://www.exploit-db.com/exploits/8020

Scores

EPSS 0.0263
EPSS Percentile 85.5%

Classification

CWE
CWE-22
Status draft

Affected Products (1)

yanocc/yanocc < 0.1.0

Timeline

Published Feb 11, 2009
Tracked Since Feb 18, 2026