CVE-2008-5948
BNCwi <1.04 - Path Traversal
Title source: llmDescription
Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter.
Exploits (1)
Scores
EPSS
0.0301
EPSS Percentile
86.4%
Classification
CWE
CWE-22
Status
draft
Affected Products (2)
bncwi/bncwi
< 1.04
bncwi/bncwi
Timeline
Published
Jan 23, 2009
Tracked Since
Feb 18, 2026