CVE-2008-7064
Last modified
CVE-2008-7064 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a "\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for "/" (forward slash), as demonstrated by uploading and including PHP code in an avatar file.. EPSS estimates a 3.19% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a "\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for "/" (forward slash), as demonstrated by uploading and including PHP code in an avatar file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Quicksilver Forums | Quicksilver Forums | 1.4.2 |
References
- http://secunia.com/advisories/32823Vendor Advisory
- http://www.qsfportal.com/index.php?a=newspost&t=191URL Repurposed
- http://secunia.com/advisories/32823Vendor Advisory
- http://www.qsfportal.com/index.php?a=newspost&t=191URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-7064?
How severe is CVE-2008-7064?
How do I fix CVE-2008-7064?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-7058Cross-site request forgery (CSRF) vulnerability in BandSite …
- CVE-2008-7059SQL injection vulnerability in index.php in One-News Beta 2 …
- CVE-2008-7060Multiple cross-site scripting (XSS) vulnerabilities in One-N…
- CVE-2008-7061The tooltip manager (chrome/views/tooltip_manager.cc) in Goo…
- CVE-2008-7062Unrestricted file upload vulnerability in admin/index.php in…
- CVE-2008-7063Ocean12 FAQ Manager Pro stores sensitive data under the web …
- CVE-2008-7065Siemens C450 IP and C475 IP VoIP devices allow remote attack…
- CVE-2008-7066OpenForum 0.66 Beta allows remote attackers to bypass authen…
- CVE-2008-7067PHP remote file inclusion vulnerability in admin/plugins/Onl…
- CVE-2008-7068The dba_replace function in PHP 5.2.6 and 4.x allows context…
- CVE-2008-7069All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive info…
- CVE-2008-7070Argument injection vulnerability in the URI handler in KVIrc…
Are you affected by CVE-2008-7064?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
