CMSimple 3.1 - Local File Inclusion

By
Anandhu K A
Published on
01 Oct 2021
Vulnerability

A directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1 allows remote attackers to include and execute arbitrary local files via a dot dot(..) in the sl parameter to index.php when register globals are enabled. By including adm.php and then invoking the upload action, this can be utilised for remote file execution.

Mitigation / Precaution

The vendor patched 3.1 without changing the version number.


Written by
Anandhu K A
Anandhu K A
Lead Engineer
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days