10
CVSSv2

CVE-2008-6833

Published: 22/06/2009 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in commsrss.php in fuzzylime (cms) prior to 3.01b allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in a files array element for a blogs action, as demonstrated by the files[0] parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

fuzzylime fuzzylime \\(cms\\) 3.0.1a

fuzzylime fuzzylime \\(cms\\) 3.0

fuzzylime fuzzylime \\(cms\\) 3.0.1

Exploits

<?php ## ## Name: Fuzzylime 301 Remote Code Execution Exploit ## Credits: Charles "real" F <charlesfol[at]hotmailfr> ## ## Conditions: None ## ## Greetz: Inphex, hEEGy and austeN ## ## Explanations ## ************ ## ## Ok, so today we will go for a walk in the fuzzylime cms maze ## Finding vulns was easy, but finding a ...