CVE-2008-3555
Title: Wsn Forum Path Traversal / LFI
Path Traversal / LFI
Proof Of Concept
PoC Available for CVE-2008-3555
CWE Category
CWE-22
Published Date
Aug 08, 2008
Modified Date
Apr 09, 2025
Exploit Status
Available
Score
6.8
CVSS v2.0
Exploit Probability (EPSS)
3.29%
Vulnerability Summary
CVE-2008-3555: Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the TID parameter, as demonstrated by uploading a .jpg file containing PHP sequences.
Impacted Vendors
Reference Links
http://secunia.com/advisories/31392
http://securityreason.com/securityalert/4120
https://exchange.xforce.ibmcloud.com/vulnerabilities/44236
https://www.exploit-db.com/exploits/6208
http://secunia.com/advisories/31392
http://securityreason.com/securityalert/4120
https://exchange.xforce.ibmcloud.com/vulnerabilities/44236
https://www.exploit-db.com/exploits/6208
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
6.8
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:P/I:P/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2008-3555 Exploits & PoCs (Proof Of Concept)
Exploit-DB
https://www.exploit-db.com/exploits/6208
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected Stack
No specific products linked.