CVE-2008-6308 Information
Feb 14, 2021
cve
Description
Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the pun_user[language] parameter to (1) functions_navlinks.php (2) header_new_messages.php (3) profile_send.php and (4) viewtopic_PM-link.php in include/pms/.
Reference
http://secunia.com/advisories/13201 http://www.securityfocus.com/bid/32360 http://www.vupen.com/english/advisories/2008/3214 https://exchange.xforce.ibmcloud.com/vulnerabilities/46718 https://www.exploit-db.com/exploits/7159
Share on: