5.5
CVSSv2

CVE-2018-6022

Published: 23/01/2018 Updated: 12/02/2018
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms up to and including 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-office access to provide a ..\ in the param.path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

5none nonecms