- Description
- Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to pages/download/default/ops/search.php; or the admin_theme_dir parameter to (3) download.php, (4) forum.php, or (5) news.php in admin/ops/reports/ops/. NOTE: it was later reported that 1.4.2 beta and earlier are also affected for vector 1.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:N
- nvd@nist.gov
- CWE-22
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:1024_cms:1024_cms:1.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E85A736-6D17-411A-ABB1-60E4515CFE16"
},
{
"criteria": "cpe:2.3:a:1024_cms:1024_cms:1.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3018A278-32F6-4B03-95A3-393520BF5625"
},
{
"criteria": "cpe:2.3:a:1024_cms:1024_cms:1.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B5FDF8E-B71A-4462-B141-7FDBEE852184"
},
{
"criteria": "cpe:2.3:a:1024_cms:1024_cms:1.4.2:beta:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79D9509E-FAC0-404B-839C-FC89AF6613E2"
}
],
"operator": "OR"
}
]
}
]