PT-2007-6071 · Chupix · Chupix Cms

Gold_M

·

Published

2007-09-18

·

Updated

2017-09-29

·

CVE-2007-4957

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chupix CMS version 0.2.3
Description The issue allows remote attackers to read or overwrite arbitrary files, or create arbitrary directories, via directory traversal vulnerabilities in the download.php file. This is achieved by including a .. (dot dot) in the fichier or repertoire parameters for file access, or in the repertoire parameter for directory creation.
Recommendations For Chupix CMS version 0.2.3, as a temporary workaround, consider restricting access to the download.php file until a patch is available. Additionally, restrict the use of the fichier and repertoire parameters to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4957

Affected Products

Chupix Cms