← Vulnerability feed

Vulnerability record · CVE-2009-0422 · published 5 February 2009

CVE-2009-0422: Tincan phplist code injection vulnerability

Tincan · Phplist

Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SERVER[ConfigFile] parameter to admin/index.php.

7.5 CVSS 2.0 High EPSS 6.2% · top 6.7% CWE-94 · Code injection
7.5CVSS 2.0 base score
6.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SERVER[ConfigFile] parameter to admin/index.php.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0422 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2006-5322Tincan phplist vulnerabilityMultiple SQL injection vulnerabilities in phplist before 2.10.3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.EPSS 1.2%7.5CVE-2005-2432Tincan phplist vulnerabilitySQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2)…EPSS 1.3%6.8CVE-2011-0748Tincan phplist cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administr…EPSS 1.5%6.5CVE-2005-3555Tincan phplist vulnerabilityMultiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute ar…EPSS 1.6%5.0CVE-2008-5887Tincan phplist improper input validation vulnerabilityphplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."EPSS 11%5.0CVE-2006-1746Tincan phplist path traversal vulnerabilityDirectory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database…EPSS 2.4%5.0CVE-2005-3557Tincan phplist vulnerabilityDirectory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot…EPSS 2.2%5.0CVE-2005-2433Tincan phplist vulnerabilityPhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) us…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2009-0422), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.