CVE-2009-4216

Klinza Professional CMS <5.0.1 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by klinza · perlwebappsphp
https://www.exploit-db.com/exploits/33376

Scores

EPSS 0.0183
EPSS Percentile 83.0%

Details

CWE
CWE-22
Status published
Products (1)
klinza/klinza_professional_cms < 5.0.1
Published Dec 07, 2009
Tracked Since Feb 18, 2026