cpe:/a:dynpg:dynpg_cms:4.1.1 cpe:/a:dynpg:dynpg_cms:4.2.0 CVE-2010-4399 2010-12-06T08:37:31.707-05:00 2010-12-20T00:00:00.000-05:00 4.3 NETWORK MEDIUM NONE PARTIAL NONE NONE http://nvd.nist.gov 2010-12-06T09:09:00.000-05:00 EXPLOIT-DB 15646 SECUNIA 42380 BID 45115 OSVDB 69539 MISC http://packetstormsecurity.org/files/view/96230/dynpg-lfisqldisclose.txt CONFIRM http://www.dynpg.org/cms-freeware_en.php?t=DynPG+Update+4.2.1+Security+Update&read_article=226 MISC http://www.htbridge.ch/advisory/lfi_in_dynpg.html Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of these details are obtained from third party information.