PT-2008-6695 · Cms Made Simple · Cms Made Simple

M4Ck-H@Ck

·

Published

2008-12-17

·

Updated

2017-09-29

·

CVE-2008-5642

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CMS Made Simple version 1.4.1
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by using a .. (dot dot) in the cms language cookie.
Recommendations For CMS Made Simple version 1.4.1, update to a version that fixes this issue. If no specific fix is provided for version 1.4.1, consider restricting access to the admin/login.php file until a patch is available. As a temporary workaround, consider validating and sanitizing the cms language cookie to prevent directory traversal attacks.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5642

Affected Products

Cms Made Simple