CVE-2008-1409 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)
Patch early
A public exploit exists.
Description
Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.42% — more likely to be exploited than 84% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-03-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| exero | exero cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Exero CMS 1.0.1 - 'theme' Multiple Local File Inclusions | 2008-03-17 |
References
- http://www.securityfocus.com/bid/28273
- http://www.vupen.com/english/advisories/2008/0909/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41238
- https://www.exploit-db.com/exploits/5265
- http://www.securityfocus.com/bid/28273
- http://www.vupen.com/english/advisories/2008/0909/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41238
- https://www.exploit-db.com/exploits/5265
→ the Explorer · watch your stack · NVD