CVE-2009-1526

JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script during a backup action.
Configurations

Configuration 1 (hide)

cpe:2.3:a:directadmin:directadmin:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-05-05 20:30

Updated : 2025-12-16 21:05


NVD link : CVE-2009-1526

Mitre link : CVE-2009-1526

CVE.ORG link : CVE-2009-1526


JSON object : View

Products Affected

directadmin

  • directadmin
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')