CVE-2010-3468
Mura CMS <5.1.498-5.2.2809 & Sava CMS 5-5.2 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-3468. PoCs published by mr_me.
AI-analyzed exploit summary This is a detailed writeup describing a directory traversal vulnerability in Blue River Mura CMS. The vulnerability allows unauthenticated attackers to download arbitrary files from the server by manipulating the FILEID parameter in a GET request.
Description
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. (dot dot) in the FILEID parameter to the default URI under tasks/render/file/.
Exploits (1)
This is a detailed writeup describing a directory traversal vulnerability in Blue River Mura CMS. The vulnerability allows unauthenticated attackers to download arbitrary files from the server by manipulating the FILEID parameter in a GET request.