PT-2008-2091 · Liquid Silver · Liquid-Silver Cms

Stack-Terrorist [V40]

·

Published

2008-01-25

·

Updated

2017-09-29

·

CVE-2008-0459

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Liquid-Silver CMS version 0.35
Description The issue allows remote attackers to include and execute arbitrary local files due to a directory traversal vulnerability in the update/index.php file when magic quotes gpc is disabled. This can be achieved by using a .. (dot dot) in the update parameter.
Recommendations For Liquid-Silver CMS version 0.35, consider disabling the update/index.php file or restricting access to it until a patch is available. Additionally, enabling magic quotes gpc can help mitigate this issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0459

Affected Products

Liquid-Silver Cms