github.comConfirmation
https://github.com/CouchCMS/CouchCMS/issues/46 CVE-2018-7662
MEDIUMNuclei
CouchCMS <= 2.0 - Path Disclosure
Record summary
CVE-2018-7662 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMCouchCMS <= 2.0 - Path DisclosureCVSS 5.3
CouchCMS <= 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php.
Impact
An attacker can exploit this vulnerability to gain knowledge of the server's directory structure, potentially aiding in further attacks.
Remediation
Upgrade to the latest version of CouchCMS (2.1 or higher) to mitigate this vulnerability.
WeaknessesCWE-200
Authorsritikchaddha
Template tagscve2018cvecouchcmsfpdvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:couchcms:couch:*:*:*:*:*:*:*:*
https://github.com/CouchCMS/CouchCMS/issues/46 https://nvd.nist.gov/vuln/detail/CVE-2018-7662 https://github.com/20142995/Goby https://github.com/5ecurity/CVE-List https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-7662