PT-2008-3843 · Wr · Wr-Meeting
Cr@Zy_King
·
Published
2008-05-20
·
Updated
2017-09-29
·
CVE-2008-2355
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
WR-Meeting version 1.0
Description:
The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the
msnum parameter in a coment event, when magic quotes gpc is disabled. This is related to a directory traversal vulnerability in the index.php file.Recommendations:
For WR-Meeting version 1.0, consider disabling the
coment event or restricting access to the msnum parameter until a patch is available. Additionally, enabling magic quotes gpc may help mitigate the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wr-Meeting