Constructr CMS Directory Traversal Vulnerability
BID:32957
Info
Constructr CMS Directory Traversal Vulnerability
| Bugtraq ID: | 32957 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5860 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2008 12:00AM |
| Updated: | Jan 07 2009 08:22PM |
| Credit: | fuzion |
| Vulnerable: |
Constructr CMS Constructr CMS 3.2.5 |
| Not Vulnerable: | |
Discussion
Constructr CMS Directory Traversal Vulnerability
Constructr CMS is prone to a directory-traversal vulnerability because the application fails to adequately sanitize user-supplied input.
A successful attack may allow an attacker to view or overwrite arbitrary files on the system. This may allow arbitrary script code to run in the context of the webserver.
Constructr CMS 3.02.5 and prior versions are vulnerable.
Constructr CMS is prone to a directory-traversal vulnerability because the application fails to adequately sanitize user-supplied input.
A successful attack may allow an attacker to view or overwrite arbitrary files on the system. This may allow arbitrary script code to run in the context of the webserver.
Constructr CMS 3.02.5 and prior versions are vulnerable.
Exploit / POC
Constructr CMS Directory Traversal Vulnerability
An attacker can exploit this issue using standard client applications.
An attacker can exploit this issue using standard client applications.
Solution / Fix
Constructr CMS Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Constructr CMS Directory Traversal Vulnerability
References:
References:
- Constructr CMS Home Page (Constructr CMS)