7.5
CVSSv2

CVE-2008-5776

Published: 30/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in Aperto Blog 0.1.1 allow remote malicious users to include and execute arbitrary local files via directory traversal sequences in the (1) action parameter to admin.php and the (2) get parameter to index.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

Vulnerable Product Search on Vulmon Subscribe to Product

apertoblog apertoblog 0.1.1

Exploits

=========================================================================================================== [o] Aperto Blog 011 Local File Inclusion and SQL Injection Vulnerabilities Software : Aperto Blog version 011 Vendor : codegooglecom/p/apertoblog/ Download : codegooglecom/p/apertoblog/do ...