
CVE-2009-1444 – WebPortal CMS 0.8b - Multiple Local/Remote File Inclusions
https://notcve.org/view.php?id=CVE-2009-1444
27 Apr 2009 — PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter. Una vulnerabilidad de inclusión remota de archivo PHP en indexk.php en WebPortal CMS v0.8-beta permite a atacantes remotos ejecutar código PHP arbitrario a través de una URL en el parámetro lib_path. • https://www.exploit-db.com/exploits/8516 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2009-1445 – WebPortal CMS 0.8b - Multiple Local/Remote File Inclusions
https://notcve.org/view.php?id=CVE-2009-1445
27 Apr 2009 — Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequences in the lang parameter to libraries/helpdocs/help.php and (2) include and execute arbitrary local files via directory traversal sequences in the error parameter to index.php. Múltiples vulnerabilidades de salto de directorio en WebPortal CMS v0.8-beta permiten a atacantes remotos (1) leer ficheros de su elección a través de secuencias de salto de director... • https://www.exploit-db.com/exploits/8516 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •