Security Advisory

CVE-2008-1409

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-03-20 10:00:00
Last updated 2024-08-07 08:24:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php.