PT-2008-4903 · Lovecms · Lovecms

Pomdapimp

·

Published

2008-08-07

·

Updated

2017-09-29

·

CVE-2008-3509

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LoveCMS version 1.6.2
Description The issue allows remote attackers to change the configuration or execute arbitrary PHP code due to the lack of administrative authentication for certain files in the system/admin/ directory. Specifically, this affects the addblock.php, blocks.php, and themes.php files.
Recommendations For LoveCMS version 1.6.2, consider restricting access to the addblock.php, blocks.php, and themes.php files in the system/admin/ directory until a patch is available. As a temporary workaround, implement proper administrative authentication for these files to prevent unauthorized changes or code execution.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3509

Affected Products

Lovecms