CVE-2008-7118
UnknownEPSS 2.44%
Last modified
CVE-2008-7118 is a vulnerability of currently unknown severity. WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.. EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Webidsupport | Webid | 0.5.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-7118?
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.
How severe is CVE-2008-7118?
Severity scoring for CVE-2008-7118 is pending analysis. The EPSS model estimates a 2.44% probability of exploitation in the next 30 days.
How do I fix CVE-2008-7118?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-7112The Scanner File Utility (aka listener) in Kyocera Mita (KM)…
- CVE-2008-7113The Scanner File Utility (aka listener) in Kyocera Mita (KM)…
- CVE-2008-7114SQL injection vulnerability in members_search.php in iFusion…
- CVE-2008-7115The web interface to the Belkin Wireless G router and ADSL2 …
- CVE-2008-7116SQL injection vulnerability in the admin panel (admin/) in W…
- CVE-2008-7117eledicss.php in WeBid auction script 0.5.4 allows remote att…
- CVE-2008-7119SQL injection vulnerability in item.php in WeBid auction scr…
- CVE-2008-7120SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP…
- CVE-2008-7121Cross-site scripting (XSS) vulnerability in Mr. CGI Guy Hot …
- CVE-2008-7122Multiple insecure method vulnerabilities in an ActiveX contr…
- CVE-2008-7123Static code injection vulnerability in admin/configuration/m…
- CVE-2008-7124zKup CMS 2.0 through 2.3 does not require administrative aut…
Are you affected by CVE-2008-7118?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
