3.6
CVSSv2

CVE-2008-1371

Published: 18/03/2008 Updated: 08/08/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 365
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote malicious users to read and execute arbitrary files via a full pathname in the d_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

drake team drake cms 0.4.11_rc8

Exploits

source: wwwsecurityfocuscom/bid/28165/info Drake CMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input Exploiting this issue may allow an unauthorized user to view files and execute local scripts Drake CMS 0411_RC8 is vulnerable; other versions may also be affected www ...