CVE-2008-5748: Path Traversal
Published Dec 29, 2008
·Updated
Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.
Affected Software
1 affected component
bloofox bloofoxCMS=0.3.4
Event History
Dec 29, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:24 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5748?
CVE-2008-5748 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2008-5748?
To fix CVE-2008-5748, update to a patched version of BloofoxCMS or modify the code to sanitize the input parameters correctly.
3
What systems are affected by CVE-2008-5748?
CVE-2008-5748 specifically affects BloofoxCMS version 0.3.4.
4
What type of vulnerability is CVE-2008-5748?
CVE-2008-5748 is a directory traversal vulnerability, allowing attackers to read arbitrary files.
5
What parameters are exploited in CVE-2008-5748?
CVE-2008-5748 exploits the lang, theme, and module parameters to access unauthorized files.