5
CVSSv2

CVE-2008-6843

Published: 02/07/2009 Updated: 11/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote malicious users to read arbitrary files via a .. (dot dot) in the sup3r parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

netenberg fantastico_de_luxe

cpanel cpanel 11.21

cpanel cpanel 11.8.6_stable

cpanel cpanel 11.16

cpanel cpanel 11

cpanel cpanel 11.18.1

cpanel cpanel 11.18.3

cpanel cpanel 11.22.3

cpanel cpanel 11.18.4

cpanel cpanel 11.23.1_current

cpanel cpanel 11.18.2

cpanel cpanel 11.22.1

cpanel cpanel 11.4.19

cpanel cpanel 11.8.6

cpanel cpanel 11.23.1

cpanel cpanel 11.22

cpanel cpanel 11.18

cpanel cpanel 11.19.3

cpanel cpanel 11.22.2

Exploits

source: wwwsecurityfocuscom/bid/32578/info Fantastico is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability to view files and execute local scripts in the context of the webserver process This may aid in further attacks set_time_limit(0); i ...