CVE-2008-3165
fuzzylime 3.01a - Path Traversal
Title source: llmDescription
Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter, as demonstrated using content.php, a different vector than CVE-2007-4805.
Exploits (1)
References (6)
Scores
EPSS
0.0703
EPSS Percentile
91.5%
Details
CWE
CWE-22
Status
published
Products (1)
fuzzylime/fuzzylime_cms
< 3.01
Published
Jul 14, 2008
Tracked Since
Feb 18, 2026