CVE-2008-5953

KTPCCD CMS - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter to the default URI.

Exploits (1)

exploitdb WORKING POC VERIFIED
by CWH Underground · perlwebappsphp
https://www.exploit-db.com/exploits/7304

Scores

EPSS 0.0383
EPSS Percentile 88.2%

Details

CWE
CWE-22
Status published
Products (1)
ktp_computer_customer_database/ktp_computer_customer_database _nil_
Published Jan 23, 2009
Tracked Since Feb 18, 2026