4.3
CVSSv2

CVE-2008-5748

Published: 29/12/2008 Updated: 26/01/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote malicious users to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

bloofox bloofoxcms 0.3.4

Exploits

BloofoxCMS 034 wwwbloofoxcom/ magic_quotes_gpc = Off register_globals = On - File Inclusion - site/bloofoxCMS_034/plugins/spaw2/dialogs/dialogphp?lang=////////////etc/passwd%00 Also vulnerable: dialogphp?theme=<lfi> dialogphp?dialog=foo&module=<lfi> - Seasons Greetings - - nu ...