Vulnerability Description
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the com parameter to (1) cContactus.php, (2) cGuestbook.php, and (3) cArticle.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kjetiltroan | Webmaid Cms | <= 0.2-6 |
Related Weaknesses (CWE)
References
- http://inj3ct0r.com/exploits/11394Exploit
- http://packetstormsecurity.org/1003-exploits/webmaid-rfilfi.txtExploit
- http://www.exploit-db.com/exploits/11831Exploit
- http://www.securityfocus.com/bid/38993Exploit
- http://www.vupen.com/english/advisories/2010/0674Vendor Advisory
- http://inj3ct0r.com/exploits/11394Exploit
- http://packetstormsecurity.org/1003-exploits/webmaid-rfilfi.txtExploit
- http://www.exploit-db.com/exploits/11831Exploit
- http://www.securityfocus.com/bid/38993Exploit
- http://www.vupen.com/english/advisories/2010/0674Vendor Advisory
FAQ
What is CVE-2010-1267?
CVE-2010-1267 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the com parameter to (1) cContact...
How severe is CVE-2010-1267?
CVE-2010-1267 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-1267?
Check the references section above for vendor advisories and patch information. Affected products include: Kjetiltroan Webmaid Cms.