CVE-2010-1267
Last modified
CVE-2010-1267 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the com parameter to (1) cContactus.php, (2) cGuestbook.php, and (3) cArticle.php.. EPSS estimates a 2.77% chance of exploitation in the next 30 days.
Description
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the com parameter to (1) cContactus.php, (2) cGuestbook.php, and (3) cArticle.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Kjetiltroan | Webmaid Cms | <= 0.2-6 | Beta |
References
- http://www.vupen.com/english/advisories/2010/0674Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0674Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-1267?
How severe is CVE-2010-1267?
How do I fix CVE-2010-1267?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-1261The IE8 Developer Toolbar in Microsoft Internet Explorer 8 S…
- CVE-2010-1262Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows r…
- CVE-2010-1263Windows Shell and WordPad in Microsoft Windows XP SP2 and SP…
- CVE-2010-1264Unspecified vulnerability in Microsoft Windows SharePoint Se…
- CVE-2010-1265SQL injection vulnerability in Adam Corley dcsFlashGames (co…
- CVE-2010-1266Multiple PHP remote file inclusion vulnerabilities in WebMai…
- CVE-2010-1268Directory traversal vulnerability in index.php in justVisual…
- CVE-2010-1269SQL injection vulnerability in auktion.php in phpscripte24 N…
- CVE-2010-1270SQL injection vulnerability in auktion.php in Multi Auktions…
- CVE-2010-1271SQL injection vulnerability in showplugs.php in smartplugs 1…
- CVE-2010-1272PHP remote file inclusion vulnerability in includes/tgpinc.p…
- CVE-2010-1273Emweb Wt before 3.1.1 does not validate the UTF-8 encoding o…
Are you affected by CVE-2010-1267?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
