First published: Mon Jun 30 2008(Updated: )
Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the currentpath parameter, in conjunction with certain ... (triple dot) and ..... sequences in the currentfile parameter, to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usualtool CMS | =1.4a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2913 has a medium severity rating due to its potential for remote code execution.
To fix CVE-2008-2913, update to a secure version of Devalcms or implement input validation to sanitize user input.
CVE-2008-2913 affects Devalcms version 1.4a when magic_quotes_gpc is disabled.
CVE-2008-2913 is a directory traversal vulnerability that can lead to arbitrary file inclusion.
Yes, CVE-2008-2913 can be exploited remotely by attackers to execute arbitrary local files.