6.8
CVSSv2

CVE-2008-3165

Published: 14/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the p parameter, as demonstrated using content.php, a different vector than CVE-2007-4805.

Vulnerable Product Search on Vulmon Subscribe to Product

fuzzylime fuzzylime cms

Exploits

#!/usr/bin/perl # # fuzzylime 301 Perl exploit # # discovered & written by Ams # ax330d@gmailcom # # DESCRIPTION: # There are availability to load files through script # rssphp, and also there are unfiltered extract(); usage # This exploit creates shell in /code/counter/middle_index_incphp # # USAGE: # Run exploit: perl explpl www ...