CVE-2008-6926
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the scriptpath_show parameter in a GoAhead action. NOTE: this issue only crosses privilege boundaries when security settings such as disable_functions and safe_mode are active, since exploitation requires uploading of executable code to a home directory.
Una vulnerabilidad de salto de directorio en el archivo autoinstall4imagesgalleryupgrade.php en el Módulo Fantástico De Luxe para cPanel, permite a atacantes remotos incluir y ejecutar archivos locales arbitrarios por medio de secuencias de salto de directorio en el parámetro scriptpath_show en una acción GoAhead. NOTA: este problema solo cruza los límites de privilegios cuando las configuraciones de seguridad, como disable_functions y safe_mode, están activas, ya que la explotación requiere la carga de código ejecutable en un directorio de inicio.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-08-10 CVE Reserved
- 2009-08-10 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.netenberg.com/forum/index.php?topic=6832 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/497964/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/498526 | Mailing List | |
http://www.securityfocus.com/archive/1/498529 | Mailing List | |
http://www.securityfocus.com/archive/1/498529/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46252 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/6897 | 2024-08-07 | |
http://www.securityfocus.com/archive/1/498519 | 2024-08-07 | |
http://www.securityfocus.com/bid/32016 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netenberg Search vendor "Netenberg" | Fantastico De Luxe Search vendor "Netenberg" for product "Fantastico De Luxe" | * | - |
Affected
| in | Cpanel Search vendor "Cpanel" | Cpanel Search vendor "Cpanel" for product "Cpanel" | * | - |
Safe
|