Summary
ccTiddly is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system
other attacks are also
possible.
ccTiddly 1.7.6 is vulnerable
other versions may also be affected.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2008-5949 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- ARRIS 2307 Unprotected Web Console
- AlienVault OSSIM SQL Injection and Remote Code Execution Vulnerabilities
- AlienVault OSSIM Multiple Remote Code Execution Vulnerabilities
- Atlassian JIRA FishEye and Crucible Plugins XML Parsing Unspecified Security Vulnerability
- Artmedic Kleinanzeigen File Inclusion Vulnerability