10
CVSSv2

CVE-2008-4486

Published: 08/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and previous versions, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

yerba yerba

yerba yerba 6.28

Exploits

#! /usr/bin/perl # -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= # Yerba SACphp <= 63 / Local File Inclusion Exploit # -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= # Program: Yerba SACphp # Version: <= 63 # File affected: indexphp # Download: sourceforgenet/projects/yerba/ # # # Found by Pepelux <pepelux[at]enye-seco ...
[*]~======================================================~[*] [*] Yerba SACphp <= 63 Multiple Remote Vulnerabilities [*] [*]~======================================================~[*] [?] Discovered By StAkeR - StAkeR[at]hotmail[dot]it [?] Discovered On 07/10/2008 [?] downloadssourceforgenet/yerba/SACphp-6_28tgz?modtime=1 ...