vendor:
fuzzylime cms
by:
staker
N/A
CVSS
N/A
local file inclusion / arbitrary file corruption
CWE
Product Name: fuzzylime cms
Affected Version From: Unknown
Affected Version To: 3.03a
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
fuzzylime cms <= 3.03a local inclusion / arbitrary file corruption poc
There are three vulnerabilities in the fuzzylime cms version <= 3.03a. The first vulnerability (LFI) can be exploited by accessing the confirm.php file and using the 'e' and 'list' parameters to include arbitrary files. The second vulnerability (LFI) can be exploited by accessing the display.php file and using the 'template' parameter to include arbitrary files. The third vulnerability (LFC) can be exploited by accessing the display.php file and using the 'usecache' and 's' parameters to corrupt local files.
Mitigation:
Unknown