First published: Tue May 20 2008(Updated: )
Directory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) .. (dot dot) or (2) C: folder sequences in the file parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bcoos | =1.0.10 | |
Bcoos | =1.0.12 | |
Bcoos | =1.0.13 | |
Bcoos | =1.0.11 | |
Bcoos | =1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2350 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2008-2350, update Bcoos to version 1.0.14 or later which addresses the directory traversal vulnerability.
CVE-2008-2350 affects Bcoos versions 1.0.9 through 1.0.13.
CVE-2008-2350 is a directory traversal vulnerability that allows remote attackers to read arbitrary files.
Yes, CVE-2008-2350 can be exploited remotely if an attacker can manipulate the file parameter in highlight.php.