CVE-2008-6139

WebBiscuits Modules Controller 1.1 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in faqsupport/wce.download.php in WebBiscuits Modules Controller 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by GoLd_M · textwebappsphp
https://www.exploit-db.com/exploits/6703

Scores

EPSS 0.0347
EPSS Percentile 87.3%

Classification

CWE
CWE-22
Status draft

Affected Products (1)

webbiscuits/modules_controller

Timeline

Published Feb 14, 2009
Tracked Since Feb 18, 2026