Vulnerability Details CVE-2008-0813
Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.023
EPSS Ranking 84.2%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2008-0813
-
cpe:2.3:a:xpweb:xpweb:3.0.1
-
cpe:2.3:a:xpweb:xpweb:3.3.2