CVE-2008-6308
Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execute arbitrary files via a ..
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the pun_user[language] parameter to (1) functions_navlinks.php, (2) header_new_messages.php, (3) profile_send.php, and (4) viewtopic_PM-link.php in include/pms/.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- punbb/private messaging system
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/13201Vendor Advisory
- http://www.securityfocus.com/bid/32360Exploit
- http://www.vupen.com/english/advisories/2008/3214Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46718
- https://www.exploit-db.com/exploits/7159
- http://secunia.com/advisories/13201Vendor Advisory
- http://www.securityfocus.com/bid/32360Exploit
- http://www.vupen.com/english/advisories/2008/3214Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46718
- https://www.exploit-db.com/exploits/7159
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.