vendor:
Pligg CMS
by:
Tim Coen of Curesec GmbH
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Pligg CMS
Affected Version From: 2.0.2
Affected Version To: 2.0.2
Patch Exists: NO
Related CWE: N/A
CPE: a:pligg:pligg_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Pligg CMS 2.0.2 Directory Traversal
The editor delivered with Pligg CMS is vulnerable to directory traversal, which gives an attacker that obtained admin credentials the opportunity to view any file stored on the webserver that the webserver user has access to.
Mitigation:
This issue was not fixed by the vendor.