vendor:
Exponent CMS
by:
7.5
CVSS
HIGH
Local File Inclusion, Arbitrary File Upload
CWE
Product Name: Exponent CMS
Affected Version From: 2.0.0 beta 1.1
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Exponent CMS Local File Inclusion and Arbitrary File Upload Vulnerabilities
Exponent CMS is vulnerable to a local file inclusion vulnerability and an arbitrary file upload vulnerability. An attacker can exploit these vulnerabilities to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver, and obtain sensitive information.
Mitigation:
Upgrade to a patched version of Exponent CMS.