7.5
CVSSv2

CVE-2008-5291

Published: 01/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote malicious users to include and execute arbitrary local files via directory traversal sequences in the p parameter, a different vector than CVE-2007-4805 and CVE-2008-3165.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fuzzylime fuzzylime cms 3.03

Exploits

/* --+_---=+--=_____=+++++ -- FuzzyLime 303 Local File Iclude PoC *** (-0-) -____======_+++++---'''' ***************************************__________________ -- Vuln - code/trackphp $m = $_GET[m]; $p = $_GET[p]; //1 include "settingsincphp"; if(!isset($_POST[url]) || !isset($_POST[title]) || !isset($_POST[excerpt])) { ...