CVE-2014-3975: Path Traversal
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3975?
CVE-2014-3975 has a medium severity rating due to its ability to allow remote attackers to list sensitive directory contents.
How do I fix CVE-2014-3975?
To fix CVE-2014-3975, update AuraCMS to a newer version that addresses the absolute path traversal vulnerability.
What systems are affected by CVE-2014-3975?
CVE-2014-3975 affects AuraCMS version 3.0, which contains the vulnerability in the filemanager.php component.
What kind of attack can be executed using CVE-2014-3975?
An attacker can exploit CVE-2014-3975 to list directory contents by manipulating the viewdir parameter with an absolute pathname.
Is there a risk of data exposure with CVE-2014-3975?
Yes, CVE-2014-3975 poses a risk of data exposure as it allows attackers to potentially access sensitive files on the server.