vendor:
LokiCMS
by:
JosS
5.5
CVSS
MEDIUM
Arbitrary File Check
CWE
Product Name: LokiCMS
Affected Version From: LokiCMS version 0.3.4
Affected Version To: LokiCMS version 0.3.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
LokiCMS <= 0.3.4 (index.php page) Arbitrary Check File Exploit
The vulnerability allows to verify the existence of the files and directories around the server. The exploit takes advantage of the 'index.php' page in LokiCMS version 0.3.4.
Mitigation:
Update to a patched version of LokiCMS.