vendor:
Mura CMS
by:
Steven Seeley & Rohan Stelling
N/A
CVSS
N/A
Directory Traversal
Unknown
CWE
Product Name: Mura CMS
Affected Version From: Mura CMS 5.1 < 5.1.498
Affected Version To: Mura CMS 5.2 < 5.2.2809
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Unknown
2010
Blue River Mura CMS Directory Traversal
The 'fileManager.cfc' component in affected Mura CMS versions does not properly sanitize the 'FILEID' parameter, allowing an attacker to access arbitrary files on the server.
Mitigation:
The vendor has released a patch addressing the issue. Users are advised to apply the patch as soon as possible.