CVE-2008-6843

Fantastico De Luxe - Path Traversal via sup3r Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6843. PoCs published by Super-Crystal.

AI-analyzed exploit summary This exploit targets a local file inclusion vulnerability in Fantastico, allowing an attacker to include arbitrary files and execute local scripts in the context of the webserver process. It creates a malicious PHP wrapper to bypass restrictions and includes files via a crafted GET parameter.

Description

Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot dot) in the sup3r parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Super-Crystal · phpwebappsphp
https://www.exploit-db.com/exploits/32632

This exploit targets a local file inclusion vulnerability in Fantastico, allowing an attacker to include arbitrary files and execute local scripts in the context of the webserver process. It creates a malicious PHP wrapper to bypass restrictions and includes files via a crafted GET parameter.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Fantastico (CVE-2008-6843)
No auth needed
Prerequisites: Access to a vulnerable Fantastico installation · Ability to write files in the target directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46991
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/498814/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32578

Scores

EPSS 0.0688
EPSS Percentile 93.2%

Details

CWE
CWE-22
Status published
Products (19)
cpanel/cpanel 11
cpanel/cpanel 11.4.19
cpanel/cpanel 11.8.6 stable
cpanel/cpanel 11.8.6_stable
cpanel/cpanel 11.16
cpanel/cpanel 11.18
cpanel/cpanel 11.18.1
cpanel/cpanel 11.18.2
cpanel/cpanel 11.18.3
cpanel/cpanel 11.18.4
... and 9 more
Published Jul 02, 2009
Tracked Since Feb 18, 2026