PT-2008-4279 · Exero · Exero Cms
Published
2008-06-24
·
Updated
2008-09-05
·
CVE-2008-2840
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Exero CMS versions 1.0.0 through 1.0.1
Description
The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the
theme parameter to various PHP files, including "custompage.php", "errors/404.php", "members/memberslist.php", "members/profile.php", "news/fullview.php", "news/index.php", "nopermission.php", "usercp/avatar.php", or "usercp/editpassword.php" in "themes/Default/".Recommendations
For Exero CMS versions 1.0.0 and 1.0.1, consider restricting access to the vulnerable PHP files in the "themes/Default/" directory until a patch is available.
As a temporary workaround, avoid using the
theme parameter in the affected API endpoints until the issue is resolved.
Restrict access to the "themes/Default/" directory to minimize the risk of exploitation.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exero Cms