fuzzylime (cms) 'code/track.php' Local File Include Vulnerability
BID:32475
Info
fuzzylime (cms) 'code/track.php' Local File Include Vulnerability
| Bugtraq ID: | 32475 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5291 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2008 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | Alfons Luja |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
fuzzylime (cms) 'code/track.php' Local File Include Vulnerability
'fuzzylime (cms)' is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary local script code. This can allow the attacker to obtain sensitive information that may aid in further attacks. Other attacks are also possible.
This issue affects fuzzylime (cms) 3.03; other versions may also be vulnerable.
'fuzzylime (cms)' is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary local script code. This can allow the attacker to obtain sensitive information that may aid in further attacks. Other attacks are also possible.
This issue affects fuzzylime (cms) 3.03; other versions may also be vulnerable.
Exploit / POC
fuzzylime (cms) 'code/track.php' Local File Include Vulnerability
Attackers may exploit this vulnerability via a web browser.
Attackers may exploit this vulnerability via a web browser.
Solution / Fix
fuzzylime (cms) 'code/track.php' Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected].
References
fuzzylime (cms) 'code/track.php' Local File Include Vulnerability
References:
References: