6.8
CVSSv2

CVE-2010-4330

Published: 07/12/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic prior to 1.2.9 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the p parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

pulsecms pulse cms

pulsecms pulse cms 1.2.7

pulsecms pulse cms 1.2

pulsecms pulse cms 1.18

pulsecms pulse cms 1.17

pulsecms pulse cms 1.2.4

pulsecms pulse cms 1.2.3

pulsecms pulse cms 1.1

pulsecms pulse cms 1.01

pulsecms pulse cms 1.2.2

pulsecms pulse cms 1.2.1

pulsecms pulse cms 1.0

pulsecms pulse cms 1.2.6

pulsecms pulse cms 1.2.5

pulsecms pulse cms 1.16

pulsecms pulse cms 1.15

Exploits

'Pulse CMS Basic' Local File Inclusion Vulnerability (CVE-2010-4330) Mark Stanislav - markstanislav@gmailcom I DESCRIPTION --------------------------------------- A vulnerability exists in the 'includes/controllerphp' script that allows for arbitrary local file inclusion due to a null-byte attack II TESTED VERSION ----------------------- ...
Pulse CMS Basic version 128 suffers from a local file inclusion vulnerability ...