Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2010-5281

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2010-5281
Last Modified 27 Nov 2012 12:00:00
Published 26 Nov 2012 06:55:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2010-5281

Summary

Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. NOTE: some of these details are obtained from third party information.

Vulnerable Systems

Application

  • Net4visions Ibrowser 1.4.1


References

XF - ibrowser-ibrowser-file-include(62066)

OSVDB - 68247

MISC - http://www.johnleitch.net/Vulnerabilities/CMScout.2.09.IBrowser.TinyMCE.Plugin.Local.File.Inclusion/33

SECUNIA - 41634

MISC - http://packetstormsecurity.org/1009-exploits/cmscout209-lfi.txt


Last Updated: 27 May 2016 10:49:51