7.5
CVSSv2

CVE-2010-4613

Published: 29/12/2010 Updated: 30/12/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in Hycus CMS 1.0.3 allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the site parameter to (1) index.php and (2) admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

hycus hycus cms 1.0.3

Exploits

Vulnerability ID: HTB22737 Reference: wwwhtbridgech/advisory/lfi_in_hycus_cmshtml Product: Hycus CMS Vendor: Hycus Web Development Team ( wwwhycuscom/ ) Vulnerable Version: 103 Vendor Notification: 07 December 2010 Vulnerability Type: LFI Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response Risk level: High Credit: Hi ...