PT-2009-4756 · Clicknet · Clicknet Cms

The G0Bl!N

·

Published

2009-07-05

·

Updated

2017-09-19

·

CVE-2009-2325

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Clicknet CMS version 2.1
Description A directory traversal issue exists in index.php, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the side parameter of the API endpoint.
Recommendations For Clicknet CMS version 2.1, consider restricting access to the side parameter in the index.php file until a patch is available. As a temporary workaround, avoid using the side parameter with untrusted input to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2325

Affected Products

Clicknet Cms