CVE-2008-4243

Unreal Tournament 3 WebAdmin < 1.7 - Unauthenticated Path Traversal via ImageServer URI

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4243. PoCs published by Luigi Auriemma.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Unreal Tournament 3's web interface (uWeb) in version 1.3, allowing unauthenticated attackers to download arbitrary files from the server's filesystem.

Description

Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luigi Auriemma · textremotewindows
https://www.exploit-db.com/exploits/6506

This exploit demonstrates a directory traversal vulnerability in Unreal Tournament 3's web interface (uWeb) in version 1.3, allowing unauthenticated attackers to download arbitrary files from the server's filesystem.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Unreal Tournament 3 version 1.3 (builds 3601 and 3614)
No auth needed
Prerequisites: Unreal Tournament 3 server with web interface enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit x_refsource_misc
http://aluigi.org/adv/ut3webown-adv.txt
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4317
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45292
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6506
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2635
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31926
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31272

Scores

EPSS 0.0370
EPSS Percentile 88.3%

Details

CWE
CWE-22
Status published
Products (1)
epic_games/unreal_tournament_3 1.3 build_3601 (4 CPE variants)
Published Sep 25, 2008
Tracked Since Feb 18, 2026