Lucene search

K
cveMitreCVE-2011-0903
HistoryFeb 07, 2011 - 9:00 p.m.

CVE-2011-0903

2011-02-0721:00:16
CWE-22
mitre
web.nvd.nist.gov
21
cve
2011
0903
directory traversal
ar web content manager
awcm
remote attack
arbitrary files
vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.009

Percentile

83.2%

Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibly have other unspecified impact via a … (dot dot) in the (1) awcm_theme or (2) awcm_lang cookie to (a) index.php or (b) header.php.

Affected configurations

Nvd
Node
awcm-cmsar_web_content_managerMatch2.2
VendorProductVersionCPE
awcm-cmsar_web_content_manager2.2cpe:2.3:a:awcm-cms:ar_web_content_manager:2.2:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.009

Percentile

83.2%