RULE(RULE ID:334393)

Rule General Information
Release Date: 2021-12-16
Rule Name: Free Arcade Script 1.0 Local File Inclusion Command Execution Vulnerability (CVE-2009-0731)
Severity:
CVE ID:
Rule Protection Details
Description: Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:33869
ExploitDB:8094
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
http://freearcadescript.net/download.php?type=zip&name;=freearcadescript&size;=null&file;=freearcadescriptv1.3.zip