vendor:
CMS Made Simple
by:
Inclusion Hunter Team
7,5
CVSS
HIGH
LFI
98
CWE
Product Name: CMS Made Simple
Affected Version From: 1.6.2
Affected Version To: 1.6.2
Patch Exists: YES
Related CWE: N/A
CPE: a:cms_made_simple:cms_made_simple
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
CMS Made Simple <= 1.6.2
A vulnerability exists in the GetURLContent() function of the Printing module in CMS Made Simple 1.6.2 and earlier. An attacker can exploit this vulnerability to read arbitrary files on the server by sending a specially crafted HTTP request containing an URL parameter set to a base64 encoded string of the file path.
Mitigation:
Upgrade to CMS Made Simple version 1.6.3 or later.