← Vulnerability feed

Vulnerability record · CVE-2010-4399 · published 6 December 2010

CVE-2010-4399: Dynpg path traversal vulnerability

Dynpg · Dynpg

Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of these details are obtained from third party information.

4.3 CVSS 2.0 Medium EPSS 5.6% · top 7.4% CWE-22 · Path traversal
4.3CVSS 2.0 base score
5.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of these details are obtained from third party information.

AV:N/AC:M/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-4399 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2010-4400Dynpg sql injection vulnerabilitySQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_UserId par…EPSS 2.2%5.4CVE-2020-27406Dynpg cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.EPSS 0.76%5.1CVE-2010-1299Dynpg code injection vulnerabilityMultiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals i…EPSS 11%5.0CVE-2010-4401Dynpg information exposure vulnerabilitylanguages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation pat…EPSS 5.6%4.8CVE-2021-27526Dynpg cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter.EPSS 0.79%4.8CVE-2021-27527Dynpg cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter.EPSS 0.79%4.8CVE-2021-27528Dynpg cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter.EPSS 0.79%4.8CVE-2021-27529Dynpg cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter.EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2010-4399), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.