CVE-2008-6002
web-cp <0.5.7 - Path Traversal
Title source: llmDescription
Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote attackers to read arbitrary files via a full pathname in the filelocation parameter.
Exploits (1)
References (5)
Scores
EPSS
0.0423
EPSS Percentile
88.6%
Classification
CWE
CWE-22
Status
draft
Affected Products (1)
web-cp/web-cp
Timeline
Published
Jan 28, 2009
Tracked Since
Feb 18, 2026