PT-2007-6853 · Picoflat · Picoflat Cms
Published
2007-11-10
·
Updated
2017-07-29
·
CVE-2007-5920
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PicoFlat CMS versions prior to 0.4.18
Description
The issue allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. This can be leveraged to bypass authentication and upload files by including pico insert.php or other administrative scripts.
Recommendations
For versions prior to 0.4.18, update to version 0.4.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the pico insert.php script and other administrative scripts to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Picoflat Cms