RULE(RULE ID:334069)

Rule General Information
Release Date: 2021-11-10
Rule Name: klinza professional cms Directory Traversal Vulnerability (CVE-2009-4216)
Severity:
CVE ID:
Rule Protection Details
Description: Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG parameter.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:37127
http://packetstormsecurity.org/0911-exploits/klinza-lfi.txt
https://exchange.xforce.ibmcloud.com/vulnerabilities/54429
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
http://sourceforge.net/projects/klinza/