PT-2010-1245 · Irmin · Irmin Cms
Eidelweiss
·
Published
2010-04-07
·
Updated
2010-04-08
·
CVE-2008-7254
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Irmin CMS (formerly Pepsi CMS) versions 0.5 through 0.6 BETA2
Description
A directory traversal issue exists, allowing remote attackers to include and execute arbitrary files. This is possible when register globals is enabled, and a .. (dot dot) is used in the
Root Path parameter.Recommendations
For Irmin CMS (formerly Pepsi CMS) versions 0.5 through 0.6 BETA2, consider disabling the register globals setting to mitigate the risk of exploitation. Additionally, restrict access to the includes/template-loader.php file to minimize the risk of arbitrary file inclusion. Avoid using the
Root Path parameter with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Irmin Cms