Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary PHP code via vectors related to improper handling of login failures by includes/login.php; and allow remote authenticated users to write to arbitrary files and execute arbitrary PHP code via vectors involving the (2) filename and (3) block parameters to view.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: flexera
Published: 2010-03-26T18:00:00
Updated: 2024-08-07T01:06:52.603Z
Reserved: 2010-03-18T00:00:00
Link: CVE-2010-0988
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-03-26T18:30:00.500
Modified: 2024-11-21T01:13:21.823
Link: CVE-2010-0988
Redhat
No data.