Vulnerability Details CVE-2008-5860
Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to create or read arbitrary files via directory traversal sequences in the edit_file parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 79.3%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2008-5860
-
cpe:2.3:a:constructr:constructr-cms:*
-
cpe:2.3:a:constructr:constructr-cms:3.00.0
-
cpe:2.3:a:constructr:constructr-cms:3.00.1
-
cpe:2.3:a:constructr:constructr-cms:3.00.2
-
cpe:2.3:a:constructr:constructr-cms:3.01.0
-
cpe:2.3:a:constructr:constructr-cms:3.01.1
-
cpe:2.3:a:constructr:constructr-cms:3.01.2
-
cpe:2.3:a:constructr:constructr-cms:3.01.3
-
cpe:2.3:a:constructr:constructr-cms:3.01.4
-
cpe:2.3:a:constructr:constructr-cms:3.01.5
-
cpe:2.3:a:constructr:constructr-cms:3.01.6
-
cpe:2.3:a:constructr:constructr-cms:3.01.7
-
cpe:2.3:a:constructr:constructr-cms:3.01.8
-
cpe:2.3:a:constructr:constructr-cms:3.01.9
-
cpe:2.3:a:constructr:constructr-cms:3.02.0
-
cpe:2.3:a:constructr:constructr-cms:3.02.1
-
cpe:2.3:a:constructr:constructr-cms:3.02.2
-
cpe:2.3:a:constructr:constructr-cms:3.02.3
-
cpe:2.3:a:constructr:constructr-cms:3.02.4