CVE-2009-4205
Published Dec 4, 2009Directory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action par…
Vendor/product archive
2 CVEs tagged to ringsworld / flashlight_free_edition — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
Directory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action par…
SQL injection vulnerability in read.php in Flashlight Free Edition allows remote attackers to execute arbitrary SQL commands via the id parameter.