PT-2008-4938 · Chupix · Chupix Cms
Published
2008-08-10
·
Updated
2017-08-08
·
CVE-2008-3562
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Chupix CMS version 0.1.0
Description
A directory traversal issue exists in the Contact module of Chupix CMS, specifically in the index.php file. This issue allows remote attackers to include and execute arbitrary local files when the
magic quotes gpc setting is disabled. The vulnerability can be exploited by using a .. (dot dot) in the mods parameter.Recommendations
For Chupix CMS version 0.1.0, consider disabling the Contact module or restricting access to the
index.php file in the Contact module until a patch is available. Additionally, enabling magic quotes gpc may help mitigate this issue. However, the most effective solution would be to update or patch the software once a fix is provided by the vendor. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chupix Cms