PT-2009-4756 · Clicknet · Clicknet Cms
The G0Bl!N
·
Published
2009-07-05
·
Updated
2017-09-19
·
CVE-2009-2325
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Clicknet CMS version 2.1
Description
A directory traversal issue exists in index.php, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the
side parameter of the API endpoint.Recommendations
For Clicknet CMS version 2.1, consider restricting access to the
side parameter in the index.php file until a patch is available. As a temporary workaround, avoid using the side parameter with untrusted input to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clicknet Cms