7.5
CVSSv2

CVE-2008-6592

Published: 03/04/2009 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and previous versions, allows remote malicious users to copy, rename, and read arbitrary files via directory traversal sequences in the image parameter with a modified cache_dir parameter containing a %00 (encoded null byte).

Vulnerable Product Search on Vulmon Subscribe to Product

sqlite sqlite 1.2.2

lightneasy lightneasy 1.2.2

Exploits

# Author: __GiReX__ # mySite: girexaltervistaorg # Date: 14/04/08 # CMS: LightNEasy SQLite / no database <= 122 # Site: lightneasyorg # Advisory: Multiple Remote Vulnerabilities # Need: magic_quotes_gpc = Off magic_quotes_gpc = On / Off for SQL Injections ############################################################################ ...