6.8
CVSSv2

CVE-2010-1003

Published: 19/03/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x up to and including 3.5.5 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the langname parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

efrontlearning efront 3.5.0

efrontlearning efront 3.5.4

efrontlearning efront 3.5.3

efrontlearning efront 3.5.5

efrontlearning efront 3.5.1

efrontlearning efront 3.5.2

Exploits

source: wwwsecurityfocuscom/bid/38787/info eFront is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process This may allow the ...