PT-2008-1875 · Tuned Studios+1 · Freeze Theme+7

Alexandr Polyakov

+1

·

Publicado

2008-01-11

·

Atualizado

2018-10-15

·

CVE-2008-0231

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tuned Studios Subwoofer, Freeze Theme, Orange Cutout, Lonely Maple, Endless, Classic Theme, and Music Theme webpage templates (affected versions not specified)
Description The issue allows remote attackers to include and execute arbitrary files via ".." sequences in the page parameter of the index.php file. This can be leveraged for remote file inclusion when running in some PHP 5 environments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0231

Produtos afetados

Classic Theme
Endless
Freeze Theme
Lonely Maple
Music Theme
Orange Cutout
Php
Tuned Studios Subwoofer