Overview
- Description
- Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to pages/download/default/ops/search.php; or the admin_theme_dir parameter to (3) download.php, (4) forum.php, or (5) news.php in admin/ops/reports/ops/. NOTE: it was later reported that 1.4.2 beta and earlier are also affected for vector 1.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-22
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:1024_cms:1024_cms:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E85A736-6D17-411A-ABB1-60E4515CFE16" }, { "criteria": "cpe:2.3:a:1024_cms:1024_cms:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3018A278-32F6-4B03-95A3-393520BF5625" }, { "criteria": "cpe:2.3:a:1024_cms:1024_cms:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B5FDF8E-B71A-4462-B141-7FDBEE852184" }, { "criteria": "cpe:2.3:a:1024_cms:1024_cms:1.4.2:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79D9509E-FAC0-404B-839C-FC89AF6613E2" } ], "operator": "OR" } ] } ]