peter bassill · operator
$ cve CVE-2008-6926 JSON

CVE-2008-6926 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 4.2% (pctl 91)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the scriptpath_show parameter in a GoAhead action. NOTE: this issue only crosses privilege boundaries when security settings such as disable_functions and safe_mode are active, since exploitation requires uploading of executable code to a home directory.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS4.17% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2009-08-10
Last modified2026-06-16

Affected (2)

VendorProduct
cpanelcpanel
netenbergfantastico de luxe

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD