CVE-2008-6843: Path Traversal
Published Jul 2, 2009
·Updated
Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot dot) in the sup3r parameter.
Affected Software
20 affected components
Netenberg Fantastico De Luxe
Cpanel Cpanel=11
Cpanel Cpanel=11.4.19
Cpanel Cpanel=11.8.6-stable
Cpanel Cpanel=11.8.6_stable
Cpanel Cpanel=11.16
Cpanel Cpanel=11.18
Cpanel Cpanel=11.18.1
Cpanel Cpanel=11.18.2
Cpanel Cpanel=11.18.3
Cpanel Cpanel=11.18.4
Cpanel Cpanel=11.19.3
Cpanel Cpanel=11.21
Cpanel Cpanel=11.21-beta
Cpanel Cpanel=11.22
Cpanel Cpanel=11.22.1
Cpanel Cpanel=11.22.2
Cpanel Cpanel=11.22.3
Cpanel Cpanel=11.23.1-current
Cpanel Cpanel=11.23.1_current
Event History
Jul 2, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:30 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6843?
CVE-2008-6843 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2008-6843?
To resolve CVE-2008-6843, users should update their Fantastico installation to the latest version provided by Netenberg.
3
What systems are affected by CVE-2008-6843?
CVE-2008-6843 affects Fantastico as used with cPanel 11.x, including specific versions from 11.0 to 11.23.1.
4
What kind of attack is possible with CVE-2008-6843?
CVE-2008-6843 allows attackers to exploit directory traversal to read arbitrary files on the server.
5
Is CVE-2008-6843 commonly exploited?
While not highly publicized, CVE-2008-6843 presents a significant risk due to its nature and has the potential for exploitation.