CVE-2009-3694

Jdtmmsm Ezrecipe-zee - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in config/config.php in ezRecipe-Zee 91, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg[prePath] parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by kaMtiEz · perlwebappsphp
https://www.exploit-db.com/exploits/10050

Scores

EPSS 0.0149
EPSS Percentile 81.1%

Details

CWE
CWE-22
Status published
Products (1)
jdtmmsm/ezrecipe-zee 91
Published Oct 13, 2009
Tracked Since Feb 18, 2026