Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pomdapimp

#35414of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2008-4903
7.5
2008-08-07
Lovecms · Lovecms · CVE-2008-3509
**Name of the Vulnerable Software and Affected Versions** LoveCMS version 1.6.2 **Description** The issue allows remote attackers to change the configuration or execute arbitrary PHP code due to the lack of administrative authentication for certain files in the system/admin/ directory. Specifically, this affects the `addblock.php`, `blocks.php`, and `themes.php` files. **Recommendations** For LoveCMS version 1.6.2, consider restricting access to the `addblock.php`, `blocks.php`, and `themes.php` files in the system/admin/ directory until a patch is available. As a temporary workaround, implement proper administrative authentication for these files to prevent unauthorized changes or code execution.