5
CVSSv2

CVE-2013-7138

Published: 09/01/2014 Updated: 27/06/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the start parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

horizon quick content management system project horizon quick content management system

horizon quick content management system project horizon quick content management system 3.5.2

horizon quick content management system project horizon quick content management system 3.5.1

horizon quick content management system project horizon quick content management system 3.4

horizon quick content management system project horizon quick content management system 3.3

horizon quick content management system project horizon quick content management system 3.2

Exploits

Horizon QCMS version 40 suffers from remote SQL injection and directory traversal vulnerabilities ...