CVE-2008-4490
Phpabook < 0.8.8b - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the userInfo cookie.
Exploits (1)
Scores
EPSS
0.0330
EPSS Percentile
87.0%
Classification
CWE
CWE-22
Status
draft
Affected Products (4)
phpabook/phpabook
< 0.8.8b
phpabook/phpabook
phpabook/phpabook
phpabook/phpabook
Timeline
Published
Oct 08, 2008
Tracked Since
Feb 18, 2026