PT-2008-4419 · Cmreams · Cmreams Cms
Cracker
·
Published
2008-07-02
·
Updated
2017-09-29
·
CVE-2008-2985
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CMReams CMS version 1.3.1.1 Beta 2
Description
The issue allows remote attackers to include and execute arbitrary local files due to a directory traversal vulnerability in the load language.php file when register globals is enabled. This is achieved by using directory traversal sequences in the
page language parameter.Recommendations
For CMReams CMS version 1.3.1.1 Beta 2, consider disabling the register globals setting to mitigate the risk of exploitation. Additionally, restrict access to the load language.php file until a patch is available. Avoid using the
page language parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmreams Cms