5
CVSSv2

CVE-2014-5107

Published: 28/07/2014 Updated: 15/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

concrete5 prior to 5.6.3 allows remote malicious users to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations.php, (4) system/mail/importers.php, (5) system/mail/method.php, (6) system/permissions/file_types.php, (7) system/permissions/files.php, (8) system/permissions/tasks.php, (9) system/permissions/users.php, (10) system/seo/view.php, (11) view.php, (12) users/attributes.php, (13) scrapbook/view.php, (14) pages/attributes.php, (15) files/attributes.php, or (16) files/search.php in single_pages/dashboard/.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

concretecms concrete cms 5.4.2.2

concrete5 concrete5 5.5.0

concrete5 concrete5 5.5.1

concrete5 concrete5 5.5.2

concretecms concrete cms 5.6.1

concretecms concrete cms 5.6.1.1

concretecms concrete cms 5.6.1.2

concretecms concrete cms 5.6.2

concretecms concrete cms 5.6.2.1

concretecms concrete cms 5.4.2.1

concrete5 concrete5 5.5.2.1

concrete5 concrete5 5.6.0.1

concretecms concrete cms 5.4.2

concrete5 concrete5 5.6.0

concrete5 concrete5 5.6.0.2