First published: Tue Jan 23 2018(Updated: )
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-office access to provide a ..\ in the param.path parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
5none Nonecms | <=1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this directory traversal vulnerability is CVE-2018-6022.
The severity of CVE-2018-6022 is medium with a severity value of 6.5.
The directory traversal vulnerability in NoneCms 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-office access to provide a ..\ in the param.path parameter.
The directory traversal vulnerability affects NoneCms versions up to and including 1.3.0.
Yes, reference to this vulnerability can be found at http://blackwolfsec.cc/2018/01/22/Nonecms/.