CVE-2008-0521

Bubbling Library 1.32 - Path Traversal via URI Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0521. PoCs published by Stack.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in the Bubbling Library v1.32, allowing remote file disclosure via manipulated URI parameters in dispatcher.php.

Description

Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a .. (dot dot) in the uri parameter to dispatcher.php in (1) examples/dispatcher/framework/, (2) examples/dispatcher/, (3) examples/wizard/, and (4) PHP/, different vectors than CVE-2008-0545.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stack · textwebappsphp
https://www.exploit-db.com/exploits/5001

This exploit demonstrates a directory traversal vulnerability in the Bubbling Library v1.32, allowing remote file disclosure via manipulated URI parameters in dispatcher.php.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Bubbling Library v1.32
No auth needed
Prerequisites: Target server running Bubbling Library v1.32 with exposed dispatcher.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/40008
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5001
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27482

Scores

EPSS 0.0291
EPSS Percentile 85.2%

Details

CWE
CWE-22
Status published
Products (1)
bubbling_library/bubbling_library 1.32
Published Jan 31, 2008
Tracked Since Feb 18, 2026