5
CVSSv2

CVE-2008-4913

Published: 04/11/2008 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and previous versions allows remote malicious users to delete arbitrary files via a .. (dot dot) in the delete parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

lokicms lokicms 0.1.0

lokicms lokicms

lokicms lokicms 0.3.2b1

lokicms lokicms 0.3.1b2

lokicms lokicms 0.2.0

lokicms lokicms 0.1.0rc1

lokicms lokicms 0.3.1b1

lokicms lokicms 0.3.0

Exploits

Name : LokiCMS 033 <= Arbitrary File Delete Vulnerability Author : cOndemned Greetz : ZaBeaTy, GregStar, irk4z, doctor, Avantura ;* Usage: [target]/[lokiCMS]/adminphp?delete=[path]/[file] PoC: [target]/[lokiCMS]/adminphp?delete=/includes/Configphp Deleting Configphp will casue situation ...