CVE-2010-4330

Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter to index.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pulsecms:pulse_cms:*:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.0:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.01:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.1:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.2:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.2.1:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.2.2:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.2.3:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.2.4:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.2.5:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.2.6:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.2.7:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.15:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.16:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.17:-:basic:*:*:*:*:*
cpe:2.3:a:pulsecms:pulse_cms:1.18:-:basic:*:*:*:*:*

History

21 Nov 2024, 01:20

Type Values Removed Values Added
References () http://osvdb.org/69622 - Exploit () http://osvdb.org/69622 - Exploit
References () http://pulsecms.com/release-notes.php - () http://pulsecms.com/release-notes.php -
References () http://secunia.com/advisories/42462 - Vendor Advisory () http://secunia.com/advisories/42462 - Vendor Advisory
References () http://www.exploit-db.com/exploits/15691 - Exploit () http://www.exploit-db.com/exploits/15691 - Exploit
References () http://www.securityfocus.com/archive/1/515029/100/0/threaded - () http://www.securityfocus.com/archive/1/515029/100/0/threaded -
References () http://www.securityfocus.com/bid/45186 - Exploit () http://www.securityfocus.com/bid/45186 - Exploit
References () http://www.uncompiled.com/2010/12/pulse-cms-basic-local-file-inclusion-vulnerability-cve-2010-4330/ - () http://www.uncompiled.com/2010/12/pulse-cms-basic-local-file-inclusion-vulnerability-cve-2010-4330/ -
References () http://www.vupen.com/english/advisories/2010/3128 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/3128 - Vendor Advisory

Information

Published : 2010-12-07 13:53

Updated : 2024-11-21 01:20


NVD link : CVE-2010-4330

Mitre link : CVE-2010-4330

CVE.ORG link : CVE-2010-4330


JSON object : View

Products Affected

pulsecms

  • pulse_cms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')