6.8
CVSSv2

CVE-2008-4181

Published: 23/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module prior to 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

Vulnerable Product Search on Vulmon Subscribe to Product

netenberg fantastico de luxe

netenberg fantastico de luxe 2.10.4

netenberg fantastico de luxe 2.10.2

netenberg fantastico de luxe 2.10.0

netenberg fantastico de luxe 2.8.8

netenberg fantastico de luxe 2.8.6

netenberg fantastico de luxe 2.8.4

netenberg fantastico de luxe 2.8.2

netenberg fantastico de luxe 2.8.r14

netenberg fantastico de luxe 2.8.r13

netenberg fantastico de luxe 2.8.r6

netenberg fantastico de luxe 2.8.r5

netenberg fantastico de luxe 2.8.r18

netenberg fantastico de luxe 2.8.r17

netenberg fantastico de luxe 2.8.r16

netenberg fantastico de luxe 2.8.r15

netenberg fantastico de luxe 2.8.r8

netenberg fantastico de luxe 2.8.r7

netenberg fantastico de luxe 2.8.r10

netenberg fantastico de luxe 2.8.r9

netenberg fantastico de luxe 2.8.r1

netenberg fantastico de luxe 2.8.r2

netenberg fantastico de luxe 2.8.r19

netenberg fantastico de luxe 2.8.r12

netenberg fantastico de luxe 2.8.r11

netenberg fantastico de luxe 2.8.r4

netenberg fantastico de luxe 2.8.r3

Exploits

############################################################## Fantastico In all Version Cpanel 11x <= local File Include ############################################################## Must login to :2082 To break the protection mod_security & safe_mode: off & Disable functions : all none Vulnerable Code $licensing_servers ...