peter bassill · operator
$ cve CVE-2008-6522 JSON

CVE-2008-6522 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in the RenderFile function in ContentRender.class.php in Terracotta (aka OpenTerracotta) 0.6.1, and possibly other versions, allow remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the (1) CurrentDirectory and (2) File parameters to index.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.9% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2009-03-25
Last modified2026-06-16

Affected (1)

VendorProduct
devraj mukherjeeopenterracotta

Public exploits

SourceTitleDate
exploit-dbTerracotta - 'index.php' Local File Inclusion2008-04-01

References

→ the Explorer  ·  watch your stack  ·  NVD