PT-2010-1245 · Irmin · Irmin Cms

Eidelweiss

·

Publicado

2010-04-07

·

Atualizado

2010-04-08

·

CVE-2008-7254

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Irmin CMS (formerly Pepsi CMS) versions 0.5 through 0.6 BETA2
Description A directory traversal issue exists, allowing remote attackers to include and execute arbitrary files. This is possible when register globals is enabled, and a .. (dot dot) is used in the Root Path parameter.
Recommendations For Irmin CMS (formerly Pepsi CMS) versions 0.5 through 0.6 BETA2, consider disabling the register globals setting to mitigate the risk of exploitation. Additionally, restrict access to the includes/template-loader.php file to minimize the risk of arbitrary file inclusion. Avoid using the Root Path parameter with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7254

Produtos afetados

Irmin Cms