CVE-2010-2797: Path Traversal
Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the defaultcmslang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2797?
CVE-2010-2797 is considered a high severity vulnerability due to its potential to allow remote file inclusion and execution.
How do I fix CVE-2010-2797?
To fix CVE-2010-2797, upgrade to CMS Made Simple version 1.8.1 or later.
What software is affected by CVE-2010-2797?
CVE-2010-2797 affects multiple versions of CMS Made Simple including versions from 1.0 to 1.6.8.
What is the exploit method of CVE-2010-2797?
CVE-2010-2797 can be exploited through a directory traversal attack that sends a crafted request to admin scripts.
Is CVE-2010-2797 easily exploitable?
Yes, CVE-2010-2797 is easily exploitable by attackers who can manipulate input parameters to include arbitrary files.