CVE-2008-6833

fuzzylime_cms - Path Traversal via commsrss.php files Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6833. PoCs published by Charles Fol.

AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in Fuzzylime CMS 3.01 via the `commsrss.php` script, which uses `extract()` to simulate `register_globals=On`. It then writes malicious PHP code to a counter file, achieving remote code execution without requiring specific PHP configurations.

Description

Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a files array element for a blogs action, as demonstrated by the files[0] parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Charles Fol · phpwebappsphp
https://www.exploit-db.com/exploits/6060

This exploit leverages a file inclusion vulnerability in Fuzzylime CMS 3.01 via the `commsrss.php` script, which uses `extract()` to simulate `register_globals=On`. It then writes malicious PHP code to a counter file, achieving remote code execution without requiring specific PHP configurations.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Fuzzylime CMS 3.01
No auth needed
Prerequisites: Target must be running Fuzzylime CMS 3.01 · PHP must be configured with `allow_url_include` or similar settings enabling file operations
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43941
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6060
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/49873
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30930

Scores

EPSS 0.0856
EPSS Percentile 94.4%

Details

CWE
CWE-22
Status published
Products (3)
fuzzylime/fuzzylime_\(cms\) 3.0
fuzzylime/fuzzylime_\(cms\) 3.0.1
fuzzylime/fuzzylime_\(cms\) 3.0.1a
Published Jun 22, 2009
Tracked Since Feb 18, 2026