7.5
CVSSv2

CVE-2012-5231

Published: 01/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

miniCMS 1.0 and 2.0 allows remote malicious users to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable extension, which is not properly handled by (a) update.php when writing files to content/, or (b) updatenews.php when writing files to content/news/.

Vulnerable Product Search on Vulmon Subscribe to Product

jessgramp minicms 1.0

jessgramp minicms 2.0

Exploits

######################################################################## # Title : miniCMS v10 : v20 php inject code # Author : Or4nGM4n # Version : all version # GDork : "This site is managed using MiniCMS©" # Download : sourceforgenet/projects/mini-cms/files/mini-cms/ # Thnks : # +----------------------------------+ # | xS ...