PT-2010-1245 · Irmin · Irmin Cms

Eidelweiss

·

Published

2010-04-07

·

Updated

2010-04-08

·

CVE-2008-7254

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Irmin CMS (formerly Pepsi CMS) versions 0.5 through 0.6 BETA2
Description A directory traversal issue exists, allowing remote attackers to include and execute arbitrary files. This is possible when register globals is enabled, and a .. (dot dot) is used in the Root Path parameter.
Recommendations For Irmin CMS (formerly Pepsi CMS) versions 0.5 through 0.6 BETA2, consider disabling the register globals setting to mitigate the risk of exploitation. Additionally, restrict access to the includes/template-loader.php file to minimize the risk of arbitrary file inclusion. Avoid using the Root Path parameter with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7254

Affected Products

Irmin Cms