RETIRED: Plume CMS Multiple Remote File Include Vulnerabilities

Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

This BID is being retired because these issues are not exploitable.


 

Privacy Statement
Copyright 2010, SecurityFocus