CVE-2008-3365: Path Traversal
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when registerglobals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagefull parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3365?
CVE-2008-3365 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-3365?
To fix CVE-2008-3365, ensure that register_globals is disabled and update to a newer version of Pixelpost that addresses this vulnerability.
What are the consequences of exploiting CVE-2008-3365?
Exploiting CVE-2008-3365 allows attackers to include and execute arbitrary local files, compromising the security of the affected system.
Which versions of Pixelpost are affected by CVE-2008-3365?
CVE-2008-3365 specifically affects Pixelpost version 1.7.1.
Can CVE-2008-3365 be exploited on all operating systems?
CVE-2008-3365 is primarily a concern on systems where the vulnerable Pixelpost version is running, particularly on Microsoft Windows platforms.