5
CVSSv2

CVE-2008-5642

Published: 17/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote malicious users to read arbitrary files via a .. (dot dot) in a cms_language cookie.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cmsmadesimple cms made simple 1.4.1

Exploits

Type: Directory Traversal vulnerability (Unix tested) / Root privileges escalation Vendor: CMS Made Simple Software: CMS Made Simple 141 "Spring Garden" (and probably others ) Author: M4ck-h@cK Date 29112008 Home: sweet home contact: no, thx :) Exploit: Demo: on h[ttp://democmsmadesimplefr/admin/] GET democmsmadesimplefr/admin ...