PT-2008-3598 · Siteman · Siteman

Ircrash

+1

·

Published

2008-05-05

·

Updated

2017-09-29

·

CVE-2008-2081

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Siteman version 2.0.x2
Description A directory traversal issue exists, allowing remote authenticated administrators to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the module parameter of the index.php file.
Recommendations For Siteman version 2.0.x2, consider restricting access to the module parameter in the index.php file to prevent exploitation until a patch is available. As a temporary workaround, limit the ability of remote authenticated administrators to include and execute local files.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2081

Affected Products

Siteman