CVE-2008-6074
Published Feb 6, 2009
Last updated 6 years ago
Overview
- Description
- Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the importFunction parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.1
- Impact score
- 6.4
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-22
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:phpcrs:phpcrs:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "999D00E6-21D9-420B-95EA-1BF36FD60E31", "versionEndIncluding": "2.06" }, { "criteria": "cpe:2.3:a:phpcrs:phpcrs:1.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0994EF7-BA80-41F9-84FA-A0650D2119F6" }, { "criteria": "cpe:2.3:a:phpcrs:phpcrs:2.00:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C2D46D1-A07E-43BD-BCC9-818E5272BEA5" }, { "criteria": "cpe:2.3:a:phpcrs:phpcrs:2.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "696469A2-C176-4EB9-AB55-F792B095C5D0" }, { "criteria": "cpe:2.3:a:phpcrs:phpcrs:2.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4357D021-1AF8-4F83-AE16-B5B005F749BE" }, { "criteria": "cpe:2.3:a:phpcrs:phpcrs:2.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98BABC5E-3280-47E5-B492-1840CF2B2292" }, { "criteria": "cpe:2.3:a:phpcrs:phpcrs:2.04:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5750153-CF0A-440D-91BB-8EBDA2272473" }, { "criteria": "cpe:2.3:a:phpcrs:phpcrs:2.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD8FEC8D-A333-4ADF-B05F-6322419BA96F" } ], "operator": "OR" } ] } ]