CVE-2008-5642: Path Traversal
Published Dec 17, 2008
·Updated
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a cmslanguage cookie.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=1.4.1
Event History
Dec 17, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5642?
CVE-2008-5642 is classified as a medium severity vulnerability due to its potential for exploitation in reading arbitrary files.
2
How do I fix CVE-2008-5642?
To fix CVE-2008-5642, upgrade CMS Made Simple to version 1.4.2 or later, which addresses this directory traversal vulnerability.
3
What are the potential impacts of CVE-2008-5642?
The potential impacts of CVE-2008-5642 include unauthorized access to sensitive files on the server, leading to information disclosure.
4
What systems are affected by CVE-2008-5642?
CVE-2008-5642 specifically affects CMS Made Simple version 1.4.1.
5
Who is at risk from CVE-2008-5642?
Any users or administrators running CMS Made Simple version 1.4.1 are at risk of CVE-2008-5642 exploitation.