7.8
CVSSv2

CVE-2008-0513

Published: 31/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote malicious users to read arbitrary files via a .. (dot dot) in the file parameter to parser/parser.php, as demonstrated by a filename ending with %00.gif, a different vector than CVE-2005-1840.

Vulnerable Product Search on Vulmon Subscribe to Product

phpcms phpcms 1.2.2

Exploits

Digital Security Research Group [DSecRG] Advisory #DSECRG-08-005 Application: phpCMS Versions Affected: 122 Vendor URL: wwwphpcmsde Bug: Remote File Disclosure, Get admin password Exploits: YES Reported: 100 ...