// For flags

CVE-2014-5107

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations.php, (4) system/mail/importers.php, (5) system/mail/method.php, (6) system/permissions/file_types.php, (7) system/permissions/files.php, (8) system/permissions/tasks.php, (9) system/permissions/users.php, (10) system/seo/view.php, (11) view.php, (12) users/attributes.php, (13) scrapbook/view.php, (14) pages/attributes.php, (15) files/attributes.php, or (16) files/search.php in single_pages/dashboard/.

concrete5 anterior a 5.6.3 permite a atacantes remotos obtener la ruta de instalación a través de una solicitud directa en (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations.php, (4) system/mail/importers.php, (5) system/mail/method.php, (6) system/permissions/file_types.php, (7) system/permissions/files.php, (8) system/permissions/tasks.php, (9) system/permissions/users.php, (10) system/seo/view.php, (11) view.php, (12) users/attributes.php, (13) scrapbook/view.php, (14) pages/attributes.php, (15) files/attributes.php o (16) files/search.php en single_pages/dashboard/.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-07-28 CVE Reserved
  • 2014-07-28 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Concrete5
Search vendor "Concrete5"
Concrete5
Search vendor "Concrete5" for product "Concrete5"
5.5.0
Search vendor "Concrete5" for product "Concrete5" and version "5.5.0"
-
Affected
Concrete5
Search vendor "Concrete5"
Concrete5
Search vendor "Concrete5" for product "Concrete5"
5.5.1
Search vendor "Concrete5" for product "Concrete5" and version "5.5.1"
-
Affected
Concrete5
Search vendor "Concrete5"
Concrete5
Search vendor "Concrete5" for product "Concrete5"
5.5.2
Search vendor "Concrete5" for product "Concrete5" and version "5.5.2"
-
Affected
Concrete5
Search vendor "Concrete5"
Concrete5
Search vendor "Concrete5" for product "Concrete5"
5.5.2.1
Search vendor "Concrete5" for product "Concrete5" and version "5.5.2.1"
-
Affected
Concrete5
Search vendor "Concrete5"
Concrete5
Search vendor "Concrete5" for product "Concrete5"
5.6.0
Search vendor "Concrete5" for product "Concrete5" and version "5.6.0"
-
Affected
Concrete5
Search vendor "Concrete5"
Concrete5
Search vendor "Concrete5" for product "Concrete5"
5.6.0.1
Search vendor "Concrete5" for product "Concrete5" and version "5.6.0.1"
-
Affected
Concrete5
Search vendor "Concrete5"
Concrete5
Search vendor "Concrete5" for product "Concrete5"
5.6.0.2
Search vendor "Concrete5" for product "Concrete5" and version "5.6.0.2"
-
Affected
Concretecms
Search vendor "Concretecms"
Concrete Cms
Search vendor "Concretecms" for product "Concrete Cms"
5.4.2
Search vendor "Concretecms" for product "Concrete Cms" and version "5.4.2"
-
Affected
Concretecms
Search vendor "Concretecms"
Concrete Cms
Search vendor "Concretecms" for product "Concrete Cms"
5.4.2.1
Search vendor "Concretecms" for product "Concrete Cms" and version "5.4.2.1"
-
Affected
Concretecms
Search vendor "Concretecms"
Concrete Cms
Search vendor "Concretecms" for product "Concrete Cms"
5.4.2.2
Search vendor "Concretecms" for product "Concrete Cms" and version "5.4.2.2"
-
Affected
Concretecms
Search vendor "Concretecms"
Concrete Cms
Search vendor "Concretecms" for product "Concrete Cms"
5.6.1
Search vendor "Concretecms" for product "Concrete Cms" and version "5.6.1"
-
Affected
Concretecms
Search vendor "Concretecms"
Concrete Cms
Search vendor "Concretecms" for product "Concrete Cms"
5.6.1.1
Search vendor "Concretecms" for product "Concrete Cms" and version "5.6.1.1"
-
Affected
Concretecms
Search vendor "Concretecms"
Concrete Cms
Search vendor "Concretecms" for product "Concrete Cms"
5.6.1.2
Search vendor "Concretecms" for product "Concrete Cms" and version "5.6.1.2"
-
Affected
Concretecms
Search vendor "Concretecms"
Concrete Cms
Search vendor "Concretecms" for product "Concrete Cms"
5.6.2
Search vendor "Concretecms" for product "Concrete Cms" and version "5.6.2"
-
Affected
Concretecms
Search vendor "Concretecms"
Concrete Cms
Search vendor "Concretecms" for product "Concrete Cms"
5.6.2.1
Search vendor "Concretecms" for product "Concrete Cms" and version "5.6.2.1"
-
Affected