vendor:
phpCMS
by:
Alexandr Polyakov, Stas Svistunovich
4.3
CVSS
MEDIUM
Remote File Disclosure, Get admin password
200
CWE
Product Name: phpCMS
Affected Version From: 1.2.2002
Affected Version To: 1.2.2002
Patch Exists: YES
Related CWE: N/A
CPE: a:phpcms:phpcms:1.2.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
DSECRG-08-005
phpCMS system has remote File Disclosure vulnerability in page /parser/include/class.cache_phpcms.php. Attacker can read any files in web directory by appending a valid extension with null byte to file like a “%00.gif” or smth. Also attacker can read admin password from file /parser/include/config.php.
Mitigation:
Upgrade to version 1.2.3