7.5
CVSSv2

CVE-2008-3568

Published: 10/08/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UNAK-CMS 1.5.5 allows remote malicious users to include and execute arbitrary local files via a full pathname in the Dirroot parameter, a different vulnerability than CVE-2006-4890.1.

Vulnerable Product Search on Vulmon Subscribe to Product

unak unak-cms 1.5.5

Exploits

source: wwwsecurityfocuscom/bid/30533/info UNAK-CMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability using directory-traversal strings to view local files within the context of the webserver process Information harvested may aid in furthe ...