5.1
CVSSv2

CVE-2010-0967

Published: 16/03/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote malicious users to include and execute arbitrary local files via directory traversal sequences in the style parameter to (1) colorvoid/footer.php, (2) default-green/footer.php, (3) default-orange/footer.php, and (4) default/footer.php in themes/. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

geekhelps admp 1.01

Exploits

#########################local file include / sql injection################# Author: ItSecTeam download from:geekhelpsnet/downloadphp script:ADMP remote:yes dork::D *********************lfi******************* vul1:/path/themes/colorvoid/footerphp include("/themes/$style/infophp"); ?> line 3 vuls:themes/default-green/footerphp t ...