5
CVSSv2

CVE-2017-9428

Published: 04/06/2017 Updated: 06/06/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS up to and including 4.2.18 on Windows, allowing malicious users to read arbitrary files via ..\ sequences in the directory parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bigtreecms bigtree_cms