CVE-2008-6926

N/A Unknown
Published: August 10, 2009 Modified: April 23, 2026
View on NVD

Description

Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the scriptpath_show parameter in a GoAhead action. NOTE: this issue only crosses privilege boundaries when security settings such as disable_functions and safe_mode are active, since exploitation requires uploading of executable code to a home directory.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.securityfocus.com/bid/32016
Source: cve@mitre.org
Exploit
http://www.netenberg.com/forum/index.php?topic=6832
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/497964/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/498519
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.securityfocus.com/archive/1/498526
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/498529
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/498529/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/32016
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/46252
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/6897
Source: af854a3a-2127-422b-91ae-364da2661108

18 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
5.6%
90th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

cpanel netenberg