Slaed · Slaed Cms · CVE-2008-0458
**Name of the Vulnerable Software and Affected Versions**
SLAED CMS version 2.5 Lite
**Description**
A directory traversal issue exists in the function/sources.php file of SLAED CMS, allowing remote attackers to include and execute arbitrary local files. This is achieved by providing a .. (dot dot) in the `newlang` parameter to the "index.php" endpoint.
**Recommendations**
For SLAED CMS version 2.5 Lite, consider restricting access to the `newlang` parameter in the "index.php" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.