Lucene search

K
cveMitreCVE-2008-5171
HistoryNov 19, 2008 - 6:11 p.m.

CVE-2008-5171

2008-11-1918:11:49
CWE-22
mitre
web.nvd.nist.gov
26
cve-2008-5171
phpblaster cms
directory traversal
vulnerability
security
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.008

Percentile

81.8%

Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) DB, (2) lang, and (3) skin parameters.

Affected configurations

Nvd
Node
phpblasterphpblaster_cmsMatch1.0rc1
VendorProductVersionCPE
phpblasterphpblaster_cms1.0cpe:2.3:a:phpblaster:phpblaster_cms:1.0:rc1:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.008

Percentile

81.8%

Related for CVE-2008-5171