CVE-2008-2350: Path Traversal
Published May 20, 2008
·Updated
Directory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) .. (dot dot) or (2) C: folder sequences in the file parameter.
Affected Software
5 affected components
bcoos bcoos=1.0.10
bcoos bcoos=1.0.12
bcoos bcoos=1.0.13
bcoos bcoos=1.0.11
bcoos bcoos=1.0.9
Event History
May 20, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2350?
CVE-2008-2350 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2008-2350?
To fix CVE-2008-2350, update Bcoos to version 1.0.14 or later which addresses the directory traversal vulnerability.
3
What versions of Bcoos are affected by CVE-2008-2350?
CVE-2008-2350 affects Bcoos versions 1.0.9 through 1.0.13.
4
What type of vulnerability is CVE-2008-2350?
CVE-2008-2350 is a directory traversal vulnerability that allows remote attackers to read arbitrary files.
5
Can CVE-2008-2350 be exploited remotely?
Yes, CVE-2008-2350 can be exploited remotely if an attacker can manipulate the file parameter in highlight.php.