CVE-2008-3555 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 79)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the TID parameter, as demonstrated by uploading a .jpg file containing PHP sequences.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 1.93% — more likely to be exploited than 79% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-08-08 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| wsn | forum |
| wsn | gallery |
| wsn | knowledge base |
| wsn | links |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Wsn (Multiple Products) - Local File Inclusion / Code Execution | 2008-08-06 |
References
- http://secunia.com/advisories/31392
- http://securityreason.com/securityalert/4120
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44236
- https://www.exploit-db.com/exploits/6208
- http://secunia.com/advisories/31392
- http://securityreason.com/securityalert/4120
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44236
- https://www.exploit-db.com/exploits/6208
→ the Explorer · watch your stack · NVD