VulnerabilityModified
CVE-2009-3787
files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two .
MEDIUM 5.0EPSS 6.58%
Does this matter?
Lower severity and a low EPSS score (6.58%). Track it; it rarely justifies an emergency change on its own.
Description
files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 6.58% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- vivvo/vivvo
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/37117Vendor Advisory
- http://www.securityfocus.com/archive/1/507358/100/0/threaded
- http://www.securityfocus.com/bid/36783Exploit
- http://www.waraxe.us/advisory-75.htmlExploit
- http://secunia.com/advisories/37117Vendor Advisory
- http://www.securityfocus.com/archive/1/507358/100/0/threaded
- http://www.securityfocus.com/bid/36783Exploit
- http://www.waraxe.us/advisory-75.htmlExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.