Lucene search

K
nvd[email protected]NVD:CVE-2008-5171
HistoryNov 19, 2008 - 6:11 p.m.

CVE-2008-5171

2008-11-1918:11:49
CWE-22
web.nvd.nist.gov
1

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.008

Percentile

81.8%

Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) DB, (2) lang, and (3) skin parameters.

Affected configurations

Nvd
Node
phpblasterphpblaster_cmsMatch1.0rc1
VendorProductVersionCPE
phpblasterphpblaster_cms1.0cpe:2.3:a:phpblaster:phpblaster_cms:1.0:rc1:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.008

Percentile

81.8%

Related for NVD:CVE-2008-5171