Record summary

CVE-2018-7662 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMCouchCMS <= 2.0 - Path DisclosureCVSS 5.3

CouchCMS <= 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php.

Impact

An attacker can exploit this vulnerability to gain knowledge of the server's directory structure, potentially aiding in further attacks.

Remediation

Upgrade to the latest version of CouchCMS (2.1 or higher) to mitigate this vulnerability.

WeaknessesCWE-200
Authorsritikchaddha
Template tagscve2018cvecouchcmsfpdvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:couchcms:couch:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2