← Back

CVE-2008-1856

nvd nist
Published: Apr 16, 2008Modified: Apr 23, 2026

JSON object

Loading...
5.1
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 4.9 / Impact: 6.4
Source: NVD

Description

plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuration file, which allows remote attackers to conduct directory traversal attacks and execute arbitrary local files by placing directory traversal sequences into the maps_type configuration setting, and then sending a request to maps_view.php, which causes plugins/maps/map.main.class.php to use the modified configuration.

Affected (16)

Products: Linpha: Linpha
1 product
Linpha
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Linpha
All versions
Version 0.9.0
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9.4
Version 1.0 beta1
Version 1.0 beta2
Version 1.0 beta3
Version 1.0 rc1
Version 1.1.0
Version 1.1.1
Version 1.2.0
Version 1.3.0
Version 1.3.1
Version 1.3.2

References (14)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.