PT-2008-4938 · Chupix · Chupix Cms

Published

2008-08-10

·

Updated

2017-08-08

·

CVE-2008-3562

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chupix CMS version 0.1.0
Description A directory traversal issue exists in the Contact module of Chupix CMS, specifically in the index.php file. This issue allows remote attackers to include and execute arbitrary local files when the magic quotes gpc setting is disabled. The vulnerability can be exploited by using a .. (dot dot) in the mods parameter.
Recommendations For Chupix CMS version 0.1.0, consider disabling the Contact module or restricting access to the index.php file in the Contact module until a patch is available. Additionally, enabling magic quotes gpc may help mitigate this issue. However, the most effective solution would be to update or patch the software once a fix is provided by the vendor. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3562

Affected Products

Chupix Cms