PT-2008-3296 · Unknown · World Of Phaos

Hacker_Egy

·

Published

2008-04-11

·

Updated

2017-09-29

·

CVE-2008-1755

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions World of Phaos version 4.0.1
Description The issue allows remote attackers to read arbitrary files due to a directory traversal vulnerability in the showSource function in showSource.php. This is achieved by using directory traversal sequences in the file parameter.
Recommendations For World of Phaos version 4.0.1, consider restricting access to the showSource.php file or the showSource function until a patch is available. As a temporary workaround, avoid using the file parameter in the showSource function to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1755

Affected Products

World Of Phaos