Vulnerability Description
Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary PHP code (1) into settings.php via the menu parameter to admin_settings.php or (2) into a content/=NUMBER.php file via the title parameter to admin_new.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cms.Tut.Su | Cms Chainuk | <= 1.2 |
Related Weaknesses (CWE)
References
- http://osvdb.org/55672
- http://osvdb.org/55673
- http://www.exploit-db.com/exploits/9069
- http://osvdb.org/55672
- http://osvdb.org/55673
- http://www.exploit-db.com/exploits/9069
FAQ
What is CVE-2009-2331?
CVE-2009-2331 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary PHP code (1) into settings.php via the menu parameter to admin_settings.php or ...
How severe is CVE-2009-2331?
CVE-2009-2331 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2331?
Check the references section above for vendor advisories and patch information. Affected products include: Cms.Tut.Su Cms Chainuk.