PoC Index

CVE-2008-6308

MEDIUM 5.1EPSS 2.0%

Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the pun_user[language] parameter to (1) functions_navlinks.php, (2) header_new_messages.php, (3) profile_send.php, and (4) viewtopic_PM-link.php in include/pms/.

CVSS v2.0
5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS
2.04% chance of exploitation in the next 30 days, 80th percentile
Published
2009-02-27
Updated
2024-08-07

ExploitDB entries (1)

References

Related