PT-2010-3899 · Anodyne Productions · Anodyne Productions Simm Management System

Antisecurity

·

Published

2010-06-17

·

Updated

2017-08-17

·

CVE-2010-2313

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Anodyne Productions SIMM Management System (SMS) version 2.6.10
Description The issue allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to "index.php". This can occur when magic quotes gpc is disabled.
Recommendations For version 2.6.10, consider disabling the use of the page parameter in "index.php" until a patch is available, or enable magic quotes gpc to prevent the exploitation of this issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2313

Affected Products

Anodyne Productions Simm Management System