vendor:
moziloCMS
by:
Ams
6.4
CVSS
MEDIUM
Perl exploit
20
CWE
Product Name: moziloCMS
Affected Version From: 1.10.2001
Affected Version To: 1.10.2001
Patch Exists: NO
Related CWE: N/A
CPE: a:mozilocms:mozilocms:1.10.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
moziloCMS 1.10.1 Perl exploit
Vulnerability hides in 'download.php', which can be used to download any file. Script does not filter global params, it only checks whether local file exists.
Mitigation:
Ensure that the application is not vulnerable to directory traversal attacks.