CVE-2008-0794: Path Traversal
Published Feb 15, 2008
·Updated
Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
Affected Software
1 affected component
Affiliate Market Affiliate Market=0.1_beta
Event History
Feb 15, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0794?
CVE-2008-0794 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2008-0794?
To fix CVE-2008-0794, upgrade to a version of Affiliate Market that is not affected by this vulnerability.
3
What type of attacks can exploit CVE-2008-0794?
CVE-2008-0794 can be exploited through directory traversal attacks allowing attackers to include and execute arbitrary local files.
4
Which software is affected by CVE-2008-0794?
CVE-2008-0794 affects Affiliate Market version 0.1 BETA.
5
Can CVE-2008-0794 be mitigated without patching?
Mitigation of CVE-2008-0794 without patching typically involves restricting access controls or network segmentation to limit exposure.