7.6
CVSSv2

CVE-2008-3164

Published: 14/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 765
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected.

Vulnerable Product Search on Vulmon Subscribe to Product

fuzzylime fuzzylime cms 3.01

Exploits

source: wwwsecurityfocuscom/bid/30121/info 'fuzzylime (cms)' is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this issue to execute arbitrary local script code This can allow the attacker to obtain sensitive information that may aid in further attacks Thi ...