PT-2008-3598 · Siteman · Siteman
Ircrash
+1
·
Published
2008-05-05
·
Updated
2017-09-29
·
CVE-2008-2081
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Siteman version 2.0.x2
Description
A directory traversal issue exists, allowing remote authenticated administrators to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the
module parameter of the index.php file.Recommendations
For Siteman version 2.0.x2, consider restricting access to the
module parameter in the index.php file to prevent exploitation until a patch is available. As a temporary workaround, limit the ability of remote authenticated administrators to include and execute local files.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siteman