1 results (0.001 seconds)
CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 2
CVE-2008-2217 – Content Management System for Phprojekt 0.6.1 - File Disclosure
https://notcve.org/view.php?id=CVE-2008-2217
Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cm_imgpath parameter. Vulnerabilidad de salto de directorio en cm/graphie.php de Content Management System 0.6.1 para Phprojekt; permite a atacantes remotos incluir y ejecutar ficheros locales de su elección mediante un .. (punto punto) en el parámetro cm_imgpath. • https://www.exploit-db.com/exploits/5510 http://www.securityfocus.com/bid/28958 https://exchange.xforce.ibmcloud.com/vulnerabilities/42510 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •