ID

VAR-200806-0052


CVE

CVE-2008-2534


TITLE

Fkrauthan Phoenix_view_cms "admin/admin_frame.php" Directory Traversal Vulnerability

Trust: 0.8

sources: IVD: be8e8afe-23cd-11e6-abef-000c29c66e3d // CNNVD: CNNVD-200806-049

DESCRIPTION

Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ltarget parameter. ( Dot dot ) including ltarget Any local file may be included and executed via parameters. Phoenix View Cms is prone to a file-upload vulnerability

Trust: 2.07

sources: NVD: CVE-2008-2534 // JVNDB: JVNDB-2008-003126 // BID: 85010 // IVD: be8e8afe-23cd-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: be8e8afe-23cd-11e6-abef-000c29c66e3d

AFFECTED PRODUCTS

vendor:fkrauthanmodel:phoenix view cmsscope:eqversion:2-pre-alpha

Trust: 1.6

vendor:fkrauthanmodel:phoenix view cmsscope:lteversion:pre alpha2

Trust: 0.8

vendor:fkrauthanmodel:phoenix view cms 2-pre-alphascope: - version: -

Trust: 0.3

vendor:phoenix view cmsmodel:2-pre-alphascope: - version: -

Trust: 0.2

sources: IVD: be8e8afe-23cd-11e6-abef-000c29c66e3d // BID: 85010 // JVNDB: JVNDB-2008-003126 // CNNVD: CNNVD-200806-049 // NVD: CVE-2008-2534

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-2534
value: HIGH

Trust: 1.0

NVD: CVE-2008-2534
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200806-049
value: HIGH

Trust: 0.6

IVD: be8e8afe-23cd-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

nvd@nist.gov: CVE-2008-2534
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

IVD: be8e8afe-23cd-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: be8e8afe-23cd-11e6-abef-000c29c66e3d // JVNDB: JVNDB-2008-003126 // CNNVD: CNNVD-200806-049 // NVD: CVE-2008-2534

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.8

sources: JVNDB: JVNDB-2008-003126 // NVD: CVE-2008-2534

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200806-049

TYPE

Path traversal

Trust: 0.8

sources: IVD: be8e8afe-23cd-11e6-abef-000c29c66e3d // CNNVD: CNNVD-200806-049

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-003126

PATCH

title:Top Pageurl:http://sourceforge.net/projects/phoenixviewcms/

Trust: 0.8

sources: JVNDB: JVNDB-2008-003126

EXTERNAL IDS

db:NVDid:CVE-2008-2534

Trust: 2.9

db:EXPLOIT-DBid:5578

Trust: 1.9

db:XFid:42315

Trust: 0.9

db:CNNVDid:CNNVD-200806-049

Trust: 0.8

db:JVNDBid:JVNDB-2008-003126

Trust: 0.8

db:MILW0RMid:5578

Trust: 0.6

db:BIDid:85010

Trust: 0.3

db:IVDid:BE8E8AFE-23CD-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: be8e8afe-23cd-11e6-abef-000c29c66e3d // BID: 85010 // JVNDB: JVNDB-2008-003126 // CNNVD: CNNVD-200806-049 // NVD: CVE-2008-2534

REFERENCES

url:https://www.exploit-db.com/exploits/5578

Trust: 1.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/42315

Trust: 1.0

url:http://www.milw0rm.com/exploits/5578

Trust: 0.9

url:http://xforce.iss.net/xforce/xfdb/42315

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-2534

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-2534

Trust: 0.8

sources: BID: 85010 // JVNDB: JVNDB-2008-003126 // CNNVD: CNNVD-200806-049 // NVD: CVE-2008-2534

CREDITS

Unknown

Trust: 0.3

sources: BID: 85010

SOURCES

db:IVDid:be8e8afe-23cd-11e6-abef-000c29c66e3d
db:BIDid:85010
db:JVNDBid:JVNDB-2008-003126
db:CNNVDid:CNNVD-200806-049
db:NVDid:CVE-2008-2534

LAST UPDATE DATE

2025-04-10T23:13:04.358000+00:00


SOURCES UPDATE DATE

db:BIDid:85010date:2008-06-03T00:00:00
db:JVNDBid:JVNDB-2008-003126date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200806-049date:2008-09-05T00:00:00
db:NVDid:CVE-2008-2534date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:IVDid:be8e8afe-23cd-11e6-abef-000c29c66e3ddate:2008-06-03T00:00:00
db:BIDid:85010date:2008-06-03T00:00:00
db:JVNDBid:JVNDB-2008-003126date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200806-049date:2008-06-03T00:00:00
db:NVDid:CVE-2008-2534date:2008-06-03T15:32:00