VulnerabilityModified
CVE-2010-0989
Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via directory traversal sequences in the f parameter.
MEDIUM 5.5EPSS 1.27%
Does this matter?
Lower severity and a low EPSS score (1.27%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via directory traversal sequences in the f parameter.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- pulsecms/pulse cms
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/39011Vendor Advisory
- http://secunia.com/secunia_research/2010-48/Vendor Advisory
- http://www.osvdb.org/63167
- http://www.securityfocus.com/archive/1/510307/100/0/threaded
- http://www.securityfocus.com/bid/38947
- http://secunia.com/advisories/39011Vendor Advisory
- http://secunia.com/secunia_research/2010-48/Vendor Advisory
- http://www.osvdb.org/63167
- http://www.securityfocus.com/archive/1/510307/100/0/threaded
- http://www.securityfocus.com/bid/38947
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.