peter bassill · operator
$ cve CVE-2008-1409 JSON

CVE-2008-1409 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.42% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2008-03-20
Last modified2026-06-16

Affected (1)

VendorProduct
exeroexero cms

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD