CVE-2008-2993: Path Traversal
Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) foglang and (2) fogskin parameters, probably related to libs/required/share.inc; and possibly the (3) fogpseudo, (4) fogposted, (5) fogpassword, and (6) fogcook parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2993?
CVE-2008-2993 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-2993?
To fix CVE-2008-2993, you should upgrade FOG Forum to version 0.8.2 or later, which addresses these directory traversal vulnerabilities.
What systems are affected by CVE-2008-2993?
CVE-2008-2993 affects FOG Forum version 0.8.1 specifically.
What exploitation methods are used in CVE-2008-2993?
CVE-2008-2993 can be exploited by using directory traversal techniques to include and execute arbitrary local files.
Who can be impacted by CVE-2008-2993?
Any user of FOG Forum 0.8.1 who has not applied the necessary patches may be impacted by CVE-2008-2993.