6.8
CVSSv2

CVE-2008-7254

Published: 07/04/2010 Updated: 08/04/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enabled, allows remote malicious users to include and execute arbitrary files via a .. (dot dot) in the _Root_Path parameter. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

ermenegildo fiorito irmin cms 0.6

ermenegildo fiorito irmin cms 0.5

Exploits

######################################################## Pepsi CMS (Irmin cms) pepsi-06-BETA2 Multiple Local File Vulnerability ######################################################## fucking the Web Apps [LFI #1 - attack edition ____ __ __ __ /\ _`\ /\ \ _ ...