CVE-2008-6177
Publicwarehouse Lightblog - Path Traversal
Title source: ruleDescription
Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) username parameter to view_member.php, (2) username_post parameter to login.php, and the (3) Lightblog_username cookie parameter to check_user.php.
Exploits (1)
Scores
EPSS
0.0301
EPSS Percentile
86.4%
Classification
CWE
CWE-22
Status
draft
Affected Products (1)
publicwarehouse/lightblog
Timeline
Published
Feb 19, 2009
Tracked Since
Feb 18, 2026