6.8
CVSSv2

CVE-2008-1537

Published: 28/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

Vulnerable Product Search on Vulmon Subscribe to Product

powerscripts powerbook 1.21

Exploits

[DSECRG-08-019] Digital Security Research Group [DSecRG] Advisory Application: PowerBook Versions Affected: 121 Vendor URL: wwwpowerscriptsorg/ Bug: Local File Include Exploits: YES Reported: 01022008 Vendor Respo ...