CVE-2008-0459

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
25/01/2008
Last modified:
09/04/2025

Description

Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the update parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:liquidsilvercms:liquidsilvercms:0.3:*:*:*:*:*:*:*
cpe:2.3:a:liquidsilvercms:liquidsilvercms:0.35:*:*:*:*:*:*:*