S40 CMS 0.4.2 Path Traversal
36Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 8.7epss 1.3%
de la publicación al arma0 días
Publicada en NVD13 ago
metasploit7 abr
probabilidad de explotación
1.3%top 32% de las CVE
explotación observada
noninguna fuente lo reporta
S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending traversal sequences and a null byte to bypass file extension checks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
S40 CMS · S40 CMSReferencias
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/scanner/http/s40_traversal.rbhttps://web.archive.org/web/20110613222630/http://y-osirys.com/security/exploits/id27https://web.archive.org/web/20120531114058/http://s40.biz/https://www.exploit-db.com/exploits/17129https://www.vulncheck.com/advisories/s40-cms-path-traversal