7.5
CVSSv2

CVE-2010-4810

Published: 08/07/2011 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote malicious users to execute arbitrary PHP code via a URL in the theme_file parameter to (1) includes/window_top.php and (2) header.php, and the (3) lang_file parameter to control/common.php.

Vulnerable Product Search on Vulmon Subscribe to Product

awcm-cms ar web content manager 2.1

Exploits

[+]Exploit Title: [awcm v21 final Remote File Inclusion] [+]Date: [13-11-2010] [+]Author: LoStHaCkEr  ~  aDaM_TRoJaN [+]Software Link: [wwwawcm-cmscom] [+]Version: [v21] [+]CVE :I'M IRaQi ~ Hacker town of Musayyib [+]Contact: LoStHaCkEr[at]yahoo[dot]com ~0r~ LoStHaCkEr[at]HaCkErps sourceforgenet/projects/awcm/files/ ~~~~~~~~~~~~~~ ...