Vulnerability Details CVE-2009-4581
Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the admin parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.055
EPSS Ranking 89.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 6.8
Products affected by CVE-2009-4581
-
cpe:2.3:a:roseonlinecms:roseonlinecms:*