PT-2007-6659 · Reloadcms · Reloadcms

Published

2007-10-23

·

Updated

2018-10-15

·

CVE-2007-5650

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ReloadCMS version 1.2.7
Description A directory traversal issue in system.php allows remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the module parameter to "index.php".
Recommendations For ReloadCMS version 1.2.7, consider restricting access to the module parameter in the "index.php" endpoint to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5650

Affected Products

Reloadcms