peter bassill · operator
$ cve CVE-2008-5204 JSON

CVE-2008-5204 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.8% (pctl 78)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in PowerAward 1.1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter to (1) agb.php, (2) angemeldet.php, (3) anmelden.php, (4) charts.php, (5) external_vote.php, (6) guestbook.php, (7) impressum.php, (8) index.php, (9) rss-reader.php, (10) statistic.php, (11) teilnehmer.php, (12) topsites.php, (13) votecode.php, (14) voting.php, and (15) winner.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.85% — more likely to be exploited than 78% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2008-11-21
Last modified2026-06-16

Affected (1)

VendorProduct
powerawardpoweraward

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD