Description
Directory traversal vulnerability in the showSource function in showSource.php in World of Phaos 4.0.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by HaCkeR_EgY · textwebappsphp
https://www.exploit-db.com/exploits/5420
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/44387
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41741
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/28719
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/5420
Scores
EPSS
0.0382
EPSS Percentile
88.2%
Details
CWE
CWE-22
Status
published
Products (1)
zekewalker/world_of_phaos
4.0.1
Published
Apr 11, 2008
Tracked Since
Feb 18, 2026