6.8
CVSSv2

CVE-2008-0602

Published: 06/02/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and previous versions allows remote malicious users to include and execute arbitrary local files via directory traversal sequences in the class_name parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

all club cms all club cms

Exploits

Vulnerability: File Inclusion Software Vulnerable: All Club CMS 001f and maybe prior versions Vulnerable Code: --- function __autoload($class_name) { require_once 'includes/'$class_name 'php'; } --- Download: sourceforgenet/project/showfilesphp?group_id=209058 Server should have: Register Globals: On Magic_quotes_ ...