7.5
CVSSv2

CVE-2008-7178

Published: 08/09/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote malicious users to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

xoops uploader 1.1

Exploits

MMM MMM MMM MMM MMMMMMMMMMMMM MMMMMMMMM MMMMMMMMMM MMMMMMMMM MMMMMMMMM MMMMMMMMM MMMMMMMMM MM MMM MMM MM MMM MMM MMM MMM MMM MMM MMM MMM MMM MM ...