Vulnerability Description
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the s parameter to code/commupdate.php in a count action or (2) the heads parameter to code/newsheads.php. NOTE: the blog.php vector is already covered by CVE-2008-3164.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fuzzylime | Fuzzylime \(Cms\) | 3.0.1 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2008-6834?
CVE-2008-6834 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the s parameter to code/com...
How severe is CVE-2008-6834?
CVE-2008-6834 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-6834?
Check the references section above for vendor advisories and patch information. Affected products include: Fuzzylime Fuzzylime \(Cms\).