Vulnerability Description
Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote attackers to read arbitrary files via a full pathname in the filelocation parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Web-Cp | Web-Cp | 0.5.7 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/31979Vendor Advisory
- http://www.securityfocus.com/bid/31371Exploit
- http://www.web-cp.net/mantis/changelog_page.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45408
- https://www.exploit-db.com/exploits/6556
- http://secunia.com/advisories/31979Vendor Advisory
- http://www.securityfocus.com/bid/31371Exploit
- http://www.web-cp.net/mantis/changelog_page.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45408
- https://www.exploit-db.com/exploits/6556
FAQ
What is CVE-2008-6002?
CVE-2008-6002 is a vulnerability with a CVSS score of 7.1 (HIGH). Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote attackers to read arbitrary files via a full pathname in the filelocation paramet...
How severe is CVE-2008-6002?
CVE-2008-6002 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-6002?
Check the references section above for vendor advisories and patch information. Affected products include: Web-Cp Web-Cp.