Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language, (2) Introduction_complete, and (3) use_log parameters, different vectors than CVE-2004-2445. Reference links indicate file inclusion and script or code execution in addition to information exposure.
Publication date: Thu, 19 Feb 2009 05:30:00 +0000