5
CVSSv2

CVE-2010-3468

Published: 29/09/2010 Updated: 30/09/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 prior to 5.1.498 and 5.2 prior to 5.2.2809, and Sava CMS 5 up to and including 5.2, allows remote malicious users to read arbitrary files via a .. (dot dot) in the FILEID parameter to the default URI under tasks/render/file/.

Vulnerable Product Search on Vulmon Subscribe to Product

blueriver sava cms 5.0

blueriver sava cms 5.0.122

blueriver sava cms 5.2

blueriver mura cms 5.2

blueriver mura cms 5.1

Exploits

Sep 24, 2010 * Title: Blue River Mura CMS Directory Traversal * Version: 10 * Issue type: Directory Traversal * Affected vendor: Blue River Interactive Group * Release date: 24/09/2010 * Discovered by: Steven Seeley & Rohan Stelling Summary Mura CMS is an open source content management system which is built upon th ...
Blue River Mura CMS version 10 suffers from a directory traversal vulnerability ...