5
CVSSv2

CVE-2008-5856

Published: 06/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in scripts/export.php in ClaSS prior to 0.8.61 allows remote malicious users to read arbitrary files via directory traversal sequences in the ftype parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

class class

class class 0.8.59

class class 0.8.20

class class 0.8.14

class class 0.6.1

class class 0.6.0

class class 0.4

class class 0.8.32

class class 0.8.29

class class 0.8.26

class class 0.8

class class 0.8.0

class class 0.4.1

class class 0.4.0

class class 0.8.47

class class 0.8.40

class class 0.8.5

class class 0.5.0

class class 0.4.2

class class 0.8.56

class class 0.8.51

class class 0.8.10

class class 0.8.8

class class 0.5.2

class class 0.5.1

Exploits

ClaSS wwwlaexorg/class/ - <=0860 - magic_quotes_gpc = Off register_globals = On - File Disclosure/Download - site/Class/class/scripts/exportphp?ftype= ///path/to/Class/schoolphp ///path/to/Class/dbh_connectphp ///etc/passwd - Timeline - Author notified: Dec 19 Patch 0861: Dec 19 - Seasons Greetings - - ...