CVE-2010-4330
07.12.2010, 13:53
Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter to index.php.
Vendor | Product | Version |
---|---|---|
pulsecms | pulse_cms | 𝑥 ≤ 1.2.8 |
pulsecms | pulse_cms | 1.0 |
pulsecms | pulse_cms | 1.01 |
pulsecms | pulse_cms | 1.1 |
pulsecms | pulse_cms | 1.2 |
pulsecms | pulse_cms | 1.2.1 |
pulsecms | pulse_cms | 1.2.2 |
pulsecms | pulse_cms | 1.2.3 |
pulsecms | pulse_cms | 1.2.4 |
pulsecms | pulse_cms | 1.2.5 |
pulsecms | pulse_cms | 1.2.6 |
pulsecms | pulse_cms | 1.2.7 |
pulsecms | pulse_cms | 1.15 |
pulsecms | pulse_cms | 1.16 |
pulsecms | pulse_cms | 1.17 |
pulsecms | pulse_cms | 1.18 |
𝑥
= Vulnerable software versions
References