// For flags

CVE-2008-6126

moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to download.php and the (2) page parameter to index.php, a different vector than CVE-2008-3589.

Múltiples vulnerabilidades de salto de directorio en moziloCMS v1.10.2 y versiones anteriores permite a atacantes remotos leer ficheros de su elección al utilizar los caracteres .. (punto punto) en el parámetro (1) "file" en download.php y el parámetro (2) "page" en index.php, siendo un vector diferente que CVE-2008-3589.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-02-13 CVE Reserved
  • 2009-02-13 CVE Published
  • 2009-04-10 First Exploit
  • 2024-08-07 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
<= 1.10.2
Search vendor "Mozilo" for product "Mozilocms" and version " <= 1.10.2"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.0
Search vendor "Mozilo" for product "Mozilocms" and version "1.0"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.1
Search vendor "Mozilo" for product "Mozilocms" and version "1.1"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.1.1
Search vendor "Mozilo" for product "Mozilocms" and version "1.1.1"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.2
Search vendor "Mozilo" for product "Mozilocms" and version "1.2"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.3
Search vendor "Mozilo" for product "Mozilocms" and version "1.3"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.3.1
Search vendor "Mozilo" for product "Mozilocms" and version "1.3.1"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.4
Search vendor "Mozilo" for product "Mozilocms" and version "1.4"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.5
Search vendor "Mozilo" for product "Mozilocms" and version "1.5"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.6
Search vendor "Mozilo" for product "Mozilocms" and version "1.6"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.6.1
Search vendor "Mozilo" for product "Mozilocms" and version "1.6.1"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.6.2
Search vendor "Mozilo" for product "Mozilocms" and version "1.6.2"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.7
Search vendor "Mozilo" for product "Mozilocms" and version "1.7"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.8
Search vendor "Mozilo" for product "Mozilocms" and version "1.8"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.9
Search vendor "Mozilo" for product "Mozilocms" and version "1.9"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.9.1
Search vendor "Mozilo" for product "Mozilocms" and version "1.9.1"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.9.2
Search vendor "Mozilo" for product "Mozilocms" and version "1.9.2"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.9.3
Search vendor "Mozilo" for product "Mozilocms" and version "1.9.3"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.10
Search vendor "Mozilo" for product "Mozilocms" and version "1.10"
-
Affected
Mozilo
Search vendor "Mozilo"
Mozilocms
Search vendor "Mozilo" for product "Mozilocms"
1.10.1
Search vendor "Mozilo" for product "Mozilocms" and version "1.10.1"
-
Affected