CVE-2008-1635 Information

Description

Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected.

Reference

http://www.securityfocus.com/bid/28513 https://exchange.xforce.ibmcloud.com/vulnerabilities/41525 https://www.exploit-db.com/exploits/5324

Share on: