PT-2008-4965 · Mozilo · Mozilocms

Ams

·

Publicado

2008-08-11

·

Atualizado

2017-09-29

·

CVE-2008-3589

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions moziloCMS version 1.10.1
Description The issue allows remote attackers to read arbitrary files due to a directory traversal vulnerability in the download.php file when magic quotes gpc is disabled. This is achieved by using a .. (dot dot) in the cat parameter.
Recommendations For moziloCMS version 1.10.1, consider disabling the download.php file or restricting access to it until a patch is available. Additionally, enabling magic quotes gpc can help mitigate this issue. Avoid using the cat parameter in the download.php file until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3589

Produtos afetados

Mozilocms