← Back

CVE-2008-6834

nvd nist
Published: Jun 22, 2009Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the s parameter to code/commupdate.php in a count action or (2) the heads parameter to code/newsheads.php. NOTE: the blog.php vector is already covered by CVE-2008-3164.

Affected (2)

1 product
Fuzzylime (cms)
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fuzzylime
Version 3.0.1
Version 3.0.1a

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.