CVE-2009-1678
Bitweaver < 2.6 - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the version parameter to boards/boards_rss.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Nine:Situations:Group · phpwebappsphp
https://www.exploit-db.com/exploits/8659
Scores
EPSS
0.0125
EPSS Percentile
79.4%
Details
CWE
CWE-22
Status
published
Products (9)
bitweaver/bitweaver
1.1
bitweaver/bitweaver
1.1.1_beta
bitweaver/bitweaver
1.2.1
bitweaver/bitweaver
1.3
bitweaver/bitweaver
1.3.1
bitweaver/bitweaver
2.0.0
bitweaver/bitweaver
2.0.2
bitweaver/bitweaver
2.5
bitweaver/bitweaver
< 2.6
Published
May 18, 2009
Tracked Since
Feb 18, 2026