First published: Wed Dec 17 2008(Updated: )
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a cms_language cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple CMS | =1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5642 is classified as a medium severity vulnerability due to its potential for exploitation in reading arbitrary files.
To fix CVE-2008-5642, upgrade CMS Made Simple to version 1.4.2 or later, which addresses this directory traversal vulnerability.
The potential impacts of CVE-2008-5642 include unauthorized access to sensitive files on the server, leading to information disclosure.
CVE-2008-5642 specifically affects CMS Made Simple version 1.4.1.
Any users or administrators running CMS Made Simple version 1.4.1 are at risk of CVE-2008-5642 exploitation.