PT-2008-3843 · Wr · Wr-Meeting

Cr@Zy_King

·

Published

2008-05-20

·

Updated

2017-09-29

·

CVE-2008-2355

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: WR-Meeting version 1.0
Description: The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the msnum parameter in a coment event, when magic quotes gpc is disabled. This is related to a directory traversal vulnerability in the index.php file.
Recommendations: For WR-Meeting version 1.0, consider disabling the coment event or restricting access to the msnum parameter until a patch is available. Additionally, enabling magic quotes gpc may help mitigate the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2355

Affected Products

Wr-Meeting