6.8
CVSSv2

CVE-2008-2227

Published: 14/05/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter to (1) forum.php and (2) profile.php in infusions/rank_system/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

php-fusion forum rank system 6

Exploits

source: wwwsecurityfocuscom/bid/29077/info Forum Rank System is prone to local file-include vulnerabilities because it fails to properly sanitize user-supplied input An attacker can exploit these vulnerabilities using directory-traversal strings to view files local scripts in the context of the webserver process This may aid in further ...