Vulnerability Details CVE-2008-6833
Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a files array element for a blogs action, as demonstrated by the files[0] parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.025
EPSS Ranking 84.7%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2008-6833
-
cpe:2.3:a:fuzzylime:fuzzylime_(cms):3.0
-
cpe:2.3:a:fuzzylime:fuzzylime_(cms):3.0.1
-
cpe:2.3:a:fuzzylime:fuzzylime_(cms):3.0.1a