4
CVSSv2

CVE-2010-4835

Published: 14/09/2011 Updated: 14/02/2012
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.

Vulnerable Product Search on Vulmon Subscribe to Product

oneorzero aims 2.6.0

Exploits

[:::::::::::::::::::::::::::::::::::::: 0x1 ::::::::::::::::::::::::::::::::::::::] >> General Information Advisory/Exploit Title = OneOrZero AIMS v260 Members Edition Multiple Vulnerabilities Author = Valentin Hoebel Contact = valentin@xenuserorg [:::::::::::::::::::::::::::::::::::::: 0x2 ::::::::::::::::::::::::::::::::::::::] >&g ...