Directory traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to chmod arbitrary files to 0777 via ".." sequences in the lang parameter. Refer to:
http://sitebar.org/downloads.php and
http://teamforge.net/viewcvs/viewcvs.cgi/tags/release-3.3.9/doc/history.txt?viewmarkup for patch information.
Publication date: Thu, 18 Oct 2007 00:17:00 +0000