CVE-2008-6253 Information

Description

Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3 when register_globals is enabled allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the g_pcltar_lib_dir parameter.

Reference

http://secunia.com/advisories/32736 http://www.pluck-cms.org/index.php?file=kop11.php http://www.securityfocus.com/archive/1/498438 http://www.securityfocus.com/bid/32342 https://exchange.xforce.ibmcloud.com/vulnerabilities/46676 https://www.exploit-db.com/exploits/7153

Share on: