CVE-2008-5217

txtCMS 0.3 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by cOndemned · htmlwebappsphp
https://www.exploit-db.com/exploits/5579

Scores

EPSS 0.0330
EPSS Percentile 87.3%

Details

CWE
CWE-22
Status published
Products (1)
phpc0d3r/txtcms 0.3
Published Nov 24, 2008
Tracked Since Feb 18, 2026