PT-2008-4279 · Exero · Exero Cms

Published

2008-06-24

·

Updated

2008-09-05

·

CVE-2008-2840

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Exero CMS versions 1.0.0 through 1.0.1
Description The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to various PHP files, including "custompage.php", "errors/404.php", "members/memberslist.php", "members/profile.php", "news/fullview.php", "news/index.php", "nopermission.php", "usercp/avatar.php", or "usercp/editpassword.php" in "themes/Default/".
Recommendations For Exero CMS versions 1.0.0 and 1.0.1, consider restricting access to the vulnerable PHP files in the "themes/Default/" directory until a patch is available. As a temporary workaround, avoid using the theme parameter in the affected API endpoints until the issue is resolved. Restrict access to the "themes/Default/" directory to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2840

Affected Products

Exero Cms