CVE-2008-5860
06.01.2009, 17:30
Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to create or read arbitrary files via directory traversal sequences in the edit_file parameter.
Vendor | Product | Version |
---|---|---|
constructr | constructr-cms | 𝑥 ≤ 3.02.5 |
constructr | constructr-cms | 3.00.0:alpha |
constructr | constructr-cms | 3.00.1:alpha |
constructr | constructr-cms | 3.00.2:alpha |
constructr | constructr-cms | 3.01.0:beta |
constructr | constructr-cms | 3.01.1:beta |
constructr | constructr-cms | 3.01.2:beta |
constructr | constructr-cms | 3.01.3:beta |
constructr | constructr-cms | 3.01.4:beta |
constructr | constructr-cms | 3.01.5:beta |
constructr | constructr-cms | 3.01.6:beta |
constructr | constructr-cms | 3.01.7:beta |
constructr | constructr-cms | 3.01.8:beta |
constructr | constructr-cms | 3.01.9:beta |
constructr | constructr-cms | 3.02.0 |
constructr | constructr-cms | 3.02.1 |
constructr | constructr-cms | 3.02.2 |
constructr | constructr-cms | 3.02.3 |
constructr | constructr-cms | 3.02.4 |
𝑥
= Vulnerable software versions