Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2016


Vulnerability Score 7.5 7.5
CVE Id CVE-2008-2016
Last Modified 29 Jan 2009 01:48:58
Published 29 Apr 2008 09:07:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



PHP remote file inclusion vulnerability in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter to the default URI under install/. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

Vulnerable Systems


  • Chilkat Software Chicomas 2.0.4


BUGTRAQ - 20080427 bug report

SREASON - 3837

XF - chicomas-multiple-file-include(42144)

Last Updated: 27 May 2016 10:47:44