CVE-2009-3425
Databay Maxcms - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in includes/inc.thcms_admin_dirtree.php in MaxCMS 3.11.20b allows remote attackers to read arbitrary files via directory traversal sequences in the thCMS_root parameter.
Exploits (1)
Scores
EPSS
0.0416
EPSS Percentile
88.5%
Classification
CWE
CWE-22
Status
draft
Affected Products (1)
databay/maxcms
Timeline
Published
Sep 25, 2009
Tracked Since
Feb 18, 2026