5.1
CVSSv2

CVE-2008-5860

Published: 06/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and previous versions, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote malicious users to create or read arbitrary files via directory traversal sequences in the edit_file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

constructr constructr-cms 3.00.1

constructr constructr-cms 3.00.2

constructr constructr-cms 3.02.0

constructr constructr-cms 3.02.1

constructr constructr-cms 3.00.0

constructr constructr-cms 3.01.2

constructr constructr-cms 3.01.8

constructr constructr-cms 3.02.4

constructr constructr-cms 3.01.4

constructr constructr-cms 3.01.5

constructr constructr-cms 3.01.1

constructr constructr-cms 3.01.7

constructr constructr-cms 3.01.9

constructr constructr-cms

constructr constructr-cms 3.01.6

constructr constructr-cms 3.01.3

constructr constructr-cms 3.01.0

constructr constructr-cms 3.02.3

constructr constructr-cms 3.02.2

Exploits

Constructr CMS constructr-cmsorg/ - <= 3025 "Stable" - magic_quotes_gpc = Off register_globals = On - Directory Traversal - Source Disclosure - Arbitrary File Creation - Etc Etc Etc - site/constructr/backend/templatephp?edit_file= Db info: /config/configincphp - SQL - site/constructr/?show_page= User (urlencod ...