← Back

CVE-2008-4181

nvd nist
Published: Sep 23, 2008Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

Affected (133)

1 product
Fantastico De Luxe
Configuration A
133 vulnerable
Vulnerable SoftwareAffected Versions
Netenberg
Up to 2.8.8
Up to 2.8.2
Up to 2.10.0
Up to 2.10.4
Up to 2.10.2
Up to 2.10.0
Version 2.10.0 r10
Version 2.10.0 r11
Version 2.10.0 r12
Version 2.10.0 r13
Version 2.10.0 r14
Version 2.10.0 r15
Version 2.10.0 r16
Version 2.10.0 r1
Version 2.10.0 r2
Version 2.10.0 r3
Version 2.10.0 r4
Version 2.10.0 r5
Version 2.10.0 r6
Version 2.10.0 r7
Version 2.10.0 r9
Version 2.10.2 r10
Version 2.10.2 r11
Version 2.10.2 r12
Version 2.10.2 r13
Version 2.10.2 r14
Version 2.10.2 r15
Version 2.10.2 r16
Version 2.10.2 r17
Version 2.10.2 r18
Version 2.10.2 r19
Version 2.10.2 r1
Version 2.10.2 r20
Version 2.10.2 r21
Version 2.10.2 r22
Version 2.10.2 r23
Version 2.10.2 r24
Version 2.10.2 r25
Version 2.10.2 r26
Version 2.10.2 r27
Version 2.10.2 r28
Version 2.10.2 r29
Version 2.10.2 r2
Version 2.10.2 r30
Version 2.10.2 r31
Version 2.10.2 r32
Version 2.10.2 r33
Version 2.10.2 r34
Version 2.10.2 r35
Version 2.10.2 r36
Version 2.10.2 r37
Version 2.10.2 r38
Version 2.10.2 r39
Version 2.10.2 r3
Version 2.10.2 r40
Version 2.10.2 r41
Version 2.10.2 r42
Version 2.10.2 r43
Version 2.10.2 r44
Version 2.10.2 r45
Version 2.10.2 r4
Version 2.10.2 r5
Version 2.10.2 r6
Version 2.10.2 r7
Version 2.10.2 r8
Version 2.10.2 r9
Version 2.10.4 r10
Version 2.10.4 r11
Version 2.10.4 r12
Version 2.10.4 r13
Version 2.10.4 r14
Version 2.10.4 r15
Version 2.10.4 r16
Version 2.10.4 r17
Version 2.10.4 r1
Version 2.10.4 r2
Version 2.10.4 r3
Version 2.10.4 r4
Version 2.10.4 r5
Version 2.10.4 r6
Version 2.10.4 r7
Version 2.10.4 r8
Version 2.10.4 r9
Version 2.8.2 r10
Version 2.8.2 r11
Version 2.8.2 r1
Version 2.8.2 r2
Version 2.8.2 r3
Version 2.8.2 r4
Version 2.8.2 r5
Version 2.8.2 r6
Version 2.8.2 r7
Version 2.8.2 r8
Version 2.8.2 r9
Version 2.8.4 r1
Version 2.8.4 r2
Version 2.8.4 r3
Version 2.8.4 r4
Version 2.8.4 r5
Version 2.8.4 r6
Version 2.8.4 r7
Version 2.8.6 r1
Version 2.8.6 r2
Version 2.8.6 r3
Version 2.8.8 r10
Version 2.8.8 r1
Version 2.8.8 r2
Version 2.8.8 r3
Version 2.8.8 r4
Version 2.8.8 r5
Version 2.8.8 r6
Version 2.8.8 r7
Version 2.8.8 r8
Version 2.8.8 r9
Version 2.8.r10
Version 2.8.r11
Version 2.8.r12
Version 2.8.r13
Version 2.8.r14
Version 2.8.r15
Version 2.8.r16
Version 2.8.r17
Version 2.8.r18
Version 2.8.r19
Version 2.8.r1
Version 2.8.r2
Version 2.8.r3
Version 2.8.r4
Version 2.8.r5
Version 2.8.r6
Version 2.8.r7
Version 2.8.r8
Version 2.8.r9

References (12)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.