5
CVSSv2

CVE-2007-6604

Published: 31/12/2007 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and previous versions allow remote malicious users to read arbitrary files via a .. (dot dot) in (1) the s parameter to the admin page or (2) the pg parameter to an arbitrary module, as demonstrated by reading a password hash in a .dtb file under dati/membri/ or by executing embedded PHP code in images under uploads/avatar/.

Vulnerable Product Search on Vulmon Subscribe to Product

xcms xcms 1.82

Exploits

# _ __ _____ _____ _ __ # | '_ \ / _ \ \/ / _ \ '_ \ # | | | | __/> < __/ | | | # |_| |_|\___/_/\_\___|_| |_| # XCMS <= 182 LFI & RCE Xpl # Nexen rocked this one ;) # LFIs 127001/xcms/indexphp?pg=admin&s=/////etc/passwd\0 127001/xcms/indexphp?mod=[existing module]&pg=/////etc/pa ...