CVE-2018-8056

HIGH

Western Bridge Cobub Razor <0.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a direct request to /export.php.

Exploits (1)

exploitdb WORKING POC
by Kyhvedn · textwebappsphp
https://www.exploit-db.com/exploits/44495

References (3)

Core 3
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/Kyhvedn/CVE_Description/blob/master/Cobub_Razor_0.8.0_physical_path_leakage.md
Exploit, Third Party Advisory x_refsource_misc
https://github.com/cobub/razor/issues/162
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44495/

Scores

CVSS v3 7.5
EPSS 0.0295
EPSS Percentile 86.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
cobub/razor 0.8.0
Published Mar 11, 2018
Tracked Since Feb 18, 2026