peter bassill · operator
$ cve CVE-2008-0231 JSON

CVE-2008-0231 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) Endless, (6) Classic Theme, and (7) Music Theme webpage templates allow remote attackers to include and execute arbitrary files via ".." sequences in the page parameter. NOTE: this can be leveraged for remote file inclusion when running in some PHP 5 environments.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.51% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2008-01-11
Last modified2026-06-16

Affected (7)

VendorProduct
tuned studiosclassic theme
tuned studiosendless
tuned studiosfreeze theme
tuned studioslonely maple
tuned studiosmusic theme
tuned studiosorange cutout
tuned studiossubwoofer

Public exploits

SourceTitleDate
exploit-dbTuned Studios Templates - Local File Inclusion2008-01-09

References

→ the Explorer  ·  watch your stack  ·  NVD