5.8
CVSSv2

CVE-2008-3926

Published: 04/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote malicious users to (1) read arbitrary files via a .. (dot dot) in the env parameter in a weblog action to index.php, or (2) create arbitrary directories via a .. (dot dot) in the env parameter in a login action to admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

hans oesterholt cmme 1.12

Exploits

################################################################################################################## [+] CMME 112 (LFI/XSS/CSRF/Download Backup/MkDir) Multiple Remote Vulnerabilities [+] Discovered By SirGod [+] wwwmortal-teamorg [+] Greetz : EMINEM,Ras,Puscas_marin,ToxicBlood,M ...