vendor:
Pluck CMS
by:
Digital Security Research Group [DSecRG]
4.3
CVSS
MEDIUM
Multiple Local File Include
98
CWE
Product Name: Pluck CMS
Affected Version From: 4.5.2002
Affected Version To: 4.5.2002
Patch Exists: YES
Related CWE: N/A
CPE: a:pluck_cms:pluck_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
DSECRG-08-037
Pluck CMS has Multiple Local File Include vulnerabilities. Vulnerable GET parameters 'blogpost', 'cat' and 'file'. First discovered by AmnPardaz Security Research Team. Vendor fixed vulnerability in version 4.5.2 by blocking directly access to this file. However, attacker still can exploit this vulnerability from index.php file.
Mitigation:
Upgrade to version 4.5.2 or higher.