Directory Traversal Flaws in iXon CMS from iXon
CVE-2007-2104
Currently unrated
What is CVE-2007-2104?
Multiple directory traversal vulnerabilities exist in iXon CMS 0.30, enabling remote attackers to exploit the theme_url parameter by manipulating it with ".." (dot dot) sequences. This manipulation allows for the inclusion and execution of arbitrary local files through various scripts including index.php, page.php, search.php, single.php, and archives.php. Successful exploitation may lead to significant security breaches, including unauthorized access to sensitive information.
