PT-2008-4938 · Chupix · Chupix Cms

Publicado

2008-08-10

·

Atualizado

2017-08-08

·

CVE-2008-3562

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chupix CMS version 0.1.0
Description A directory traversal issue exists in the Contact module of Chupix CMS, specifically in the index.php file. This issue allows remote attackers to include and execute arbitrary local files when the magic quotes gpc setting is disabled. The vulnerability can be exploited by using a .. (dot dot) in the mods parameter.
Recommendations For Chupix CMS version 0.1.0, consider disabling the Contact module or restricting access to the index.php file in the Contact module until a patch is available. Additionally, enabling magic quotes gpc may help mitigate this issue. However, the most effective solution would be to update or patch the software once a fix is provided by the vendor. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3562

Produtos afetados

Chupix Cms