CVE-2020-35709: Path Traversal
Published Dec 25, 2020
·Updated
bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.
Affected Software
1 affected component
bloofox bloofoxCMS=0.5.2.1
Event History
Dec 25, 2020
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
Description
Frequently Asked Questions
1
What is CVE-2020-35709?
CVE-2020-35709 is a vulnerability in bloofoxCMS 0.5.2.1 that allows admins to upload arbitrary .php files to the media/images directory.
2
How does CVE-2020-35709 work?
CVE-2020-35709 works by exploiting a directory traversal vulnerability in bloofoxCMS 0.5.2.1.
3
What is the severity of CVE-2020-35709?
The severity of CVE-2020-35709 is medium with a CVSS score of 4.9.
4
How can I fix CVE-2020-35709?
To fix CVE-2020-35709, it is recommended to update bloofoxCMS to a version that has addressed the vulnerability.
5
Where can I find more information about CVE-2020-35709?
You can find more information about CVE-2020-35709 on the GitHub issue page: https://github.com/alexlang24/bloofoxCMS/issues/7