CVE-2008-2982 Information

Description

Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2 when register_globals is enabled allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php and the (2) language parameter to (b) account/account.php (c) downloads/downloads.php (d) forum/forum.php (e) fotogalerie/delete.php and (f) fotogalerie/fotogalerie.php in admin/features/.

Reference

https://exchange.xforce.ibmcloud.com/vulnerabilities/43258 https://www.exploit-db.com/exploits/5903

Share on: