6.4
CVSSv2

CVE-2007-6584

Published: 28/12/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to pages/download/default/ops/search.php; or the admin_theme_dir parameter to (3) download.php, (4) forum.php, or (5) news.php in admin/ops/reports/ops/. NOTE: it was later reported that 1.4.2 beta and previous versions are also affected for vector 1.

Vulnerable Product Search on Vulmon Subscribe to Product

1024 cms 1024 cms 1.3.1

1024 cms 1024 cms 1.4.1

1024 cms 1024 cms 1.4.2

Exploits

vuln: 1024 CMS 131 (LFI/SQL) Multiple Vulnerabilities script info and download: www1024cmscom author: irk4z[at]yahoopl greets to: str0ke, wacky '-----------------------------------------------------------------------------' # sql-injection: code: /admin/ops/findip/ajax/searchphp: 8 $get_users = mysql_query ...