7.5
CVSSv2

CVE-2010-2797

Published: 08/10/2010 Updated: 11/10/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple prior to 1.8.1 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642.

Vulnerable Product Search on Vulmon Subscribe to Product

cmsmadesimple cms made simple 1.0

cmsmadesimple cms made simple 1.6.3

cmsmadesimple cms made simple 1.6.5

cmsmadesimple cms made simple 1.5.1

cmsmadesimple cms made simple 1.5.3

cmsmadesimple cms made simple 1.2.1

cmsmadesimple cms made simple 1.1.1

cmsmadesimple cms made simple 1.0.3

cmsmadesimple cms made simple 1.4.1

cmsmadesimple cms made simple 1.2

cmsmadesimple cms made simple 1.1

cmsmadesimple cms made simple 1.2.2

cmsmadesimple cms made simple

cmsmadesimple cms made simple 1.5.4

cmsmadesimple cms made simple 1.6

cmsmadesimple cms made simple 1.6.1

cmsmadesimple cms made simple 1.6.2

cmsmadesimple cms made simple 1.0.8

cmsmadesimple cms made simple 1.0.7

cmsmadesimple cms made simple 1.0.6

cmsmadesimple cms made simple 1.0.4

cmsmadesimple cms made simple 1.0.5

cmsmadesimple cms made simple 1.1.3.1

cmsmadesimple cms made simple 1.7

cmsmadesimple cms made simple 1.3

cmsmadesimple cms made simple 1.3.1

cmsmadesimple cms made simple 1.4

cmsmadesimple cms made simple 1.2.4

cmsmadesimple cms made simple 1.6.7

cmsmadesimple cms made simple 1.1.2

cmsmadesimple cms made simple 1.6.4

cmsmadesimple cms made simple 1.6.6

cmsmadesimple cms made simple 1.5

cmsmadesimple cms made simple 1.5.2

cmsmadesimple cms made simple 1.2.5

cmsmadesimple cms made simple 1.2.3

cmsmadesimple cms made simple 1.1.4.1

cmsmadesimple cms made simple 1.0.1

cmsmadesimple cms made simple 1.0.2