CVE-2008-4181: Path Traversal

Published Sep 23, 2008
·
Updated

Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

Affected Software

133 affected components
Netenberg Fantastico De Luxe<=2.8.2
Netenberg Fantastico De Luxe<=2.8.8
Netenberg Fantastico De Luxe<=2.10.0
Netenberg Fantastico De Luxe<=2.10.0
Netenberg Fantastico De Luxe<=2.10.2
Netenberg Fantastico De Luxe<=2.10.4
Netenberg Fantastico De Luxe=2.8.2-r1
Netenberg Fantastico De Luxe=2.8.2-r10
Netenberg Fantastico De Luxe=2.8.2-r11
Netenberg Fantastico De Luxe=2.8.2-r2
Netenberg Fantastico De Luxe=2.8.2-r3
Netenberg Fantastico De Luxe=2.8.2-r4
Netenberg Fantastico De Luxe=2.8.2-r5
Netenberg Fantastico De Luxe=2.8.2-r6
Netenberg Fantastico De Luxe=2.8.2-r7
Netenberg Fantastico De Luxe=2.8.2-r8
Netenberg Fantastico De Luxe=2.8.2-r9
Netenberg Fantastico De Luxe=2.8.4-r1
Netenberg Fantastico De Luxe=2.8.4-r2
Netenberg Fantastico De Luxe=2.8.4-r3
Netenberg Fantastico De Luxe=2.8.4-r4
Netenberg Fantastico De Luxe=2.8.4-r5
Netenberg Fantastico De Luxe=2.8.4-r6
Netenberg Fantastico De Luxe=2.8.4-r7
Netenberg Fantastico De Luxe=2.8.6-r1
Netenberg Fantastico De Luxe=2.8.6-r2
Netenberg Fantastico De Luxe=2.8.6-r3
Netenberg Fantastico De Luxe=2.8.8-r1
Netenberg Fantastico De Luxe=2.8.8-r10
Netenberg Fantastico De Luxe=2.8.8-r2
Netenberg Fantastico De Luxe=2.8.8-r3
Netenberg Fantastico De Luxe=2.8.8-r4
Netenberg Fantastico De Luxe=2.8.8-r5
Netenberg Fantastico De Luxe=2.8.8-r6
Netenberg Fantastico De Luxe=2.8.8-r7
Netenberg Fantastico De Luxe=2.8.8-r8
Netenberg Fantastico De Luxe=2.8.8-r9
Netenberg Fantastico De Luxe=2.8.r1
Netenberg Fantastico De Luxe=2.8.r2
Netenberg Fantastico De Luxe=2.8.r3
Netenberg Fantastico De Luxe=2.8.r4
Netenberg Fantastico De Luxe=2.8.r5
Netenberg Fantastico De Luxe=2.8.r6
Netenberg Fantastico De Luxe=2.8.r7
Netenberg Fantastico De Luxe=2.8.r8
Netenberg Fantastico De Luxe=2.8.r9
Netenberg Fantastico De Luxe=2.8.r10
Netenberg Fantastico De Luxe=2.8.r11
Netenberg Fantastico De Luxe=2.8.r12
Netenberg Fantastico De Luxe=2.8.r13
Netenberg Fantastico De Luxe=2.8.r14
Netenberg Fantastico De Luxe=2.8.r15
Netenberg Fantastico De Luxe=2.8.r16
Netenberg Fantastico De Luxe=2.8.r17
Netenberg Fantastico De Luxe=2.8.r18
Netenberg Fantastico De Luxe=2.8.r19
Netenberg Fantastico De Luxe=2.10.0-r1
Netenberg Fantastico De Luxe=2.10.0-r10
Netenberg Fantastico De Luxe=2.10.0-r11
Netenberg Fantastico De Luxe=2.10.0-r12
Netenberg Fantastico De Luxe=2.10.0-r13
Netenberg Fantastico De Luxe=2.10.0-r14
Netenberg Fantastico De Luxe=2.10.0-r15
Netenberg Fantastico De Luxe=2.10.0-r16
Netenberg Fantastico De Luxe=2.10.0-r2
Netenberg Fantastico De Luxe=2.10.0-r3
Netenberg Fantastico De Luxe=2.10.0-r4
Netenberg Fantastico De Luxe=2.10.0-r5
Netenberg Fantastico De Luxe=2.10.0-r6
Netenberg Fantastico De Luxe=2.10.0-r7
Netenberg Fantastico De Luxe=2.10.0-r9
Netenberg Fantastico De Luxe=2.10.2-r1
Netenberg Fantastico De Luxe=2.10.2-r10
Netenberg Fantastico De Luxe=2.10.2-r11
Netenberg Fantastico De Luxe=2.10.2-r12
Netenberg Fantastico De Luxe=2.10.2-r13
Netenberg Fantastico De Luxe=2.10.2-r14
Netenberg Fantastico De Luxe=2.10.2-r15
Netenberg Fantastico De Luxe=2.10.2-r16
Netenberg Fantastico De Luxe=2.10.2-r17
Netenberg Fantastico De Luxe=2.10.2-r18
Netenberg Fantastico De Luxe=2.10.2-r19
Netenberg Fantastico De Luxe=2.10.2-r2
Netenberg Fantastico De Luxe=2.10.2-r20
Netenberg Fantastico De Luxe=2.10.2-r21
Netenberg Fantastico De Luxe=2.10.2-r22
Netenberg Fantastico De Luxe=2.10.2-r23
Netenberg Fantastico De Luxe=2.10.2-r24
Netenberg Fantastico De Luxe=2.10.2-r25
Netenberg Fantastico De Luxe=2.10.2-r26
Netenberg Fantastico De Luxe=2.10.2-r27
Netenberg Fantastico De Luxe=2.10.2-r28
Netenberg Fantastico De Luxe=2.10.2-r29
Netenberg Fantastico De Luxe=2.10.2-r3
Netenberg Fantastico De Luxe=2.10.2-r30
Netenberg Fantastico De Luxe=2.10.2-r31
Netenberg Fantastico De Luxe=2.10.2-r32
Netenberg Fantastico De Luxe=2.10.2-r33
Netenberg Fantastico De Luxe=2.10.2-r34
Netenberg Fantastico De Luxe=2.10.2-r35
Netenberg Fantastico De Luxe=2.10.2-r36
Netenberg Fantastico De Luxe=2.10.2-r37
Netenberg Fantastico De Luxe=2.10.2-r38
Netenberg Fantastico De Luxe=2.10.2-r39
Netenberg Fantastico De Luxe=2.10.2-r4
Netenberg Fantastico De Luxe=2.10.2-r40
Netenberg Fantastico De Luxe=2.10.2-r41
Netenberg Fantastico De Luxe=2.10.2-r42
Netenberg Fantastico De Luxe=2.10.2-r43
Netenberg Fantastico De Luxe=2.10.2-r44
Netenberg Fantastico De Luxe=2.10.2-r45
Netenberg Fantastico De Luxe=2.10.2-r5
Netenberg Fantastico De Luxe=2.10.2-r6
Netenberg Fantastico De Luxe=2.10.2-r7
Netenberg Fantastico De Luxe=2.10.2-r8
Netenberg Fantastico De Luxe=2.10.2-r9
Netenberg Fantastico De Luxe=2.10.4-r1
Netenberg Fantastico De Luxe=2.10.4-r10
Netenberg Fantastico De Luxe=2.10.4-r11
Netenberg Fantastico De Luxe=2.10.4-r12
Netenberg Fantastico De Luxe=2.10.4-r13
Netenberg Fantastico De Luxe=2.10.4-r14
Netenberg Fantastico De Luxe=2.10.4-r15
Netenberg Fantastico De Luxe=2.10.4-r16
Netenberg Fantastico De Luxe=2.10.4-r17
Netenberg Fantastico De Luxe=2.10.4-r2
Netenberg Fantastico De Luxe=2.10.4-r3
Netenberg Fantastico De Luxe=2.10.4-r4
Netenberg Fantastico De Luxe=2.10.4-r5
Netenberg Fantastico De Luxe=2.10.4-r6
Netenberg Fantastico De Luxe=2.10.4-r7
Netenberg Fantastico De Luxe=2.10.4-r8
Netenberg Fantastico De Luxe=2.10.4-r9

Event History

Sep 23, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2008-4181?

CVE-2008-4181 has been classified as a high severity vulnerability due to its potential for arbitrary file inclusion and execution.

2

How do I fix CVE-2008-4181?

To resolve CVE-2008-4181, ensure that cPanel PHP Register Globals is turned off and upgrade to a version of Netenberg Fantastico De Luxe that is 2.10.4 r19 or later.

3

What types of systems are affected by CVE-2008-4181?

CVE-2008-4181 affects versions of Netenberg Fantastico De Luxe prior to 2.10.4 r19 when the PHP Register Globals feature is enabled.

4

Who can exploit CVE-2008-4181?

CVE-2008-4181 can be exploited by remote authenticated users who can manipulate input to include arbitrary local files.

5

What are the potential impacts of CVE-2008-4181?

The potential impacts of CVE-2008-4181 include unauthorized access to sensitive information and the ability to execute malicious code on the server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203