5
CVSSv2

CVE-2010-1652

Published: 03/05/2010 Updated: 03/05/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote malicious users to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the file parameter to module.php. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

helpcenterlive hcl 2.1.7

helpcenterlive hcl 2.0.6

Exploits

# Exploit Title: Help Center Live 206(module=helpcenter&file=) Local File Inclusion # Date: 27-4-2010 # Author: 41w4r10r # Software Link : # Version: Web Application # Tested on: Apcahe/Unix # CVE : [if exists] # Dork : inurl:"module=helpcenter" # Code : --------------------------------------------------------------------------------------- ...