peter bassill · operator
$ cve CVE-2008-1755 JSON

CVE-2008-1755 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 85)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the showSource function in showSource.php in World of Phaos 4.0.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.67% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2008-04-11
Last modified2026-06-16

Affected (1)

VendorProduct
zekewalkerworld of phaos

Public exploits

SourceTitleDate
exploit-dbPhaos R4000 Version - 'file' Remote File Disclosure2008-04-09

References

→ the Explorer  ·  watch your stack  ·  NVD