PT-2007-6853 · Picoflat · Picoflat Cms

Published

2007-11-10

·

Updated

2017-07-29

·

CVE-2007-5920

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PicoFlat CMS versions prior to 0.4.18
Description The issue allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. This can be leveraged to bypass authentication and upload files by including pico insert.php or other administrative scripts.
Recommendations For versions prior to 0.4.18, update to version 0.4.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the pico insert.php script and other administrative scripts to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5920

Affected Products

Picoflat Cms