First published: Tue Mar 17 2009(Updated: )
Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NucleusCMS | =3.0 | |
NucleusCMS | =3.23 | |
NucleusCMS | =3.0_rc | |
NucleusCMS | =3.1 | |
NucleusCMS | ||
NucleusCMS | =3.21 | |
NucleusCMS | <=3.40 | |
NucleusCMS | =3.22 | |
NucleusCMS | =3.0_1 | |
NucleusCMS | =3.01 | |
NucleusCMS | =3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0929 is considered to be a high severity vulnerability due to its capability to allow unauthorized access to arbitrary files on the server.
To fix CVE-2009-0929, upgrade Nucleus CMS to version 3.40 or later where the vulnerability has been patched.
CVE-2009-0929 can be exploited by attackers using directory traversal techniques to read sensitive files on the server.
CVE-2009-0929 affects all versions of Nucleus CMS prior to 3.40.
While CVE-2009-0929 has been patched in newer versions, it remains a relevant vulnerability for systems still running affected versions.