PT-2008-6695 · Cms Made Simple · Cms Made Simple
M4Ck-H@Ck
·
Publicado
2008-12-17
·
Atualizado
2017-09-29
·
CVE-2008-5642
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CMS Made Simple version 1.4.1
Description
A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by using a .. (dot dot) in the
cms language cookie.Recommendations
For CMS Made Simple version 1.4.1, update to a version that fixes this issue. If no specific fix is provided for version 1.4.1, consider restricting access to the admin/login.php file until a patch is available. As a temporary workaround, consider validating and sanitizing the
cms language cookie to prevent directory traversal attacks.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cms Made Simple