5
CVSSv2

CVE-2008-2350

Published: 20/05/2008 Updated: 08/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in highlight.php in bcoos 1.0.9 up to and including 1.0.13 allows remote malicious users to read arbitrary files via (1) .. (dot dot) or (2) C: folder sequences in the file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

bcoos bcoos 1.0.12

bcoos bcoos 1.0.13

bcoos bcoos 1.0.9

bcoos bcoos 1.0.10

bcoos bcoos 1.0.11

Exploits

source: wwwsecurityfocuscom/bid/29275/info The 'bcoos' program is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability using directory-traversal strings to include local scripts in the context of the application This may allow the attacker to ac ...