CVE-2008-0478

Setcms - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set parameter, as demonstrated by sending a certain CLIENT_IP HTTP header in an enter action to index.php, and injecting PHP sequences into files/enter.set, which is then included by index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by RST/GHC · perlwebappsphp
https://www.exploit-db.com/exploits/4962

Scores

EPSS 0.0366
EPSS Percentile 87.9%

Details

CWE
CWE-22
Status published
Products (1)
setcms/setcms 3.6.5
Published Jan 29, 2008
Tracked Since Feb 18, 2026