peter bassill · operator
$ cve CVE-2008-5787 JSON

CVE-2008-5787 EXPLOIT

5.4
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, in conjunction with a show action.

Scoring

CVSS5.4 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
EPSS3% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2008-12-31
Last modified2026-06-16

Affected (2)

VendorProduct
arabportalarab portal
microsoftwindows

Public exploits

SourceTitleDate
exploit-dbArab Portal 2.1 (Windows) - Remote File Disclosure2008-11-06

References

→ the Explorer  ·  watch your stack  ·  NVD