PT-2017-6261 · Wonder · Wondercms

Published

2017-03-17

·

Updated

2017-03-20

·

CVE-2014-8704

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wonder CMS version 2014
Description A directory traversal issue in index.php allows remote attackers to include and execute arbitrary local files by crafting a theme.
Recommendations For Wonder CMS version 2014, consider restricting access to the index.php file until a patch is available, and avoid using crafted themes that could exploit this issue.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8704

Affected Products

Wondercms