6
CVSSv2

CVE-2007-6552

Published: 28/12/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/admin_users.php to bypass a protection mechanism against direct request.

Vulnerable Product Search on Vulmon Subscribe to Product

auracms auracms 2.2

Exploits

#!/usr/bin/perl # # Indonesian Newhack Security Advisory # ------------------------------------ # AuraCMS 22 - (admin_usersphp) Remote Add Administrator Exploit # Waktu : Dec 25 2007 04:50AM # Software : AuraCMS 22 # Vendor : wwwauracmsorg/ # Ditemukan oleh : k1tk4t | newhackorg # Lokasi : Indonesia # Penjelasan : # ...