Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-1840

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2005-1840
Last Modified 05 Sep 2008 04:50:14
Published 02 Jun 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-1840

Summary

Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.

Vulnerable Systems

Application

  • Phpcms 1.2.0

  • Phpcms 1.2.1

  • Phpcms 1.2.1 P12

  • Phpcms 1.2.1 Pl1


References

CONFIRM - http://www.phpcms.de/download/index.en.html

BUGTRAQ - 20050602 SEC-CONSULT SA20050602-1 :: Arbitrary File Inclusion in phpCMS 1.2.x

MISC - http://cvs.sourceforge.net/viewcvs.py/phpcms/phpcms/parser/include/class.layout_phpcms.php?rev=1.12.2.37&view=markup

SECUNIA - 15586


Last Updated: 27 May 2016 10:40:18