CVE-2018-16836

Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.
References
Link Resource
https://github.com/maroueneboubakri/CVE/tree/master/rubedo-cms Exploit Third Party Advisory
https://www.exploit-db.com/exploits/45385/ Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:rubedo_project:rubedo:*:*:*:*:*:*:*:*

Information

Published : 2018-09-11 04:29

Updated : 2020-02-05 02:44


NVD link : CVE-2018-16836

Mitre link : CVE-2018-16836

Products Affected
No products.
CWE