CVE-2009-4421

Simple PHP Blog <0.5.1 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the blog_language1 parameter.

Exploits (1)

exploitdb WORKING POC
by jgaliana · perlwebappsphp
https://www.exploit-db.com/exploits/10604

Scores

EPSS 0.0188
EPSS Percentile 83.2%

Details

CWE
CWE-22
Status published
Products (8)
alexander_palmo/simple_php_blog 0.3.7c
alexander_palmo/simple_php_blog 0.4.0
alexander_palmo/simple_php_blog 0.4.5
alexander_palmo/simple_php_blog 0.4.6
alexander_palmo/simple_php_blog 0.4.7
alexander_palmo/simple_php_blog 0.4.7.1
alexander_palmo/simple_php_blog 0.5.0.1
alexander_palmo/simple_php_blog < 0.5.1
Published Dec 24, 2009
Tracked Since Feb 18, 2026