5
CVSSv2

CVE-2009-3787

Published: 26/10/2009 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

files.php in Vivvo CMS 4.1.5.1 allows remote malicious users to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.

Vulnerable Product Search on Vulmon Subscribe to Product

vivvo vivvo 4.1.5.1

Exploits

[waraxe-2009-SA#075] - Remote File Disclosure in Vivvo CMS 4151 =============================================================================== Author: Janek Vind "waraxe" Date: 21 October 2009 Location: Estonia, Tartu Web: wwwwaraxeus/advisory-75html Description of vulnerable software: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ...