CVE-2010-2797

CMS Made Simple <1.8.1 - Path Traversal

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/08/01/2
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40031
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/08/02/8

Scores

EPSS 0.0039
EPSS Percentile 60.1%

Details

CWE
CWE-22
Status published
Products (32)
cmsmadesimple/cms_made_simple 1.0 (7 CPE variants)
cmsmadesimple/cms_made_simple 1.0.1
cmsmadesimple/cms_made_simple 1.0.2
cmsmadesimple/cms_made_simple 1.0.3
cmsmadesimple/cms_made_simple 1.0.4
cmsmadesimple/cms_made_simple 1.0.5
cmsmadesimple/cms_made_simple 1.0.6
cmsmadesimple/cms_made_simple 1.0.7
cmsmadesimple/cms_made_simple 1.0.8
cmsmadesimple/cms_made_simple 1.1 (4 CPE variants)
... and 22 more
Published Oct 08, 2010
Tracked Since Feb 18, 2026