CVE-2008-3555
Summary
| CVE | CVE-2008-3555 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-08-08 19:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the TID parameter, as demonstrated by uploading a .jpg file containing PHP sequences. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wsn | Forum | All | All | All | All |
| Application | Wsn | Gallery | All | All | All | All |
| Application | Wsn | Knowledge Base | All | All | All | All |
| Application | Wsn | Links | 4.0.0 | All | All | All |
| Application | Wsn | Links | 4.0.1 | All | All | All |
| Application | Wsn | Links | 4.0.10 | All | All | All |
| Application | Wsn | Links | 4.0.11 | All | All | All |
| Application | Wsn | Links | 4.0.12 | All | All | All |
| Application | Wsn | Links | 4.0.13 | All | All | All |
| Application | Wsn | Links | 4.0.14 | All | All | All |
| Application | Wsn | Links | 4.0.15 | All | All | All |
| Application | Wsn | Links | 4.0.16 | All | All | All |
| Application | Wsn | Links | 4.0.17 | All | All | All |
| Application | Wsn | Links | 4.0.18 | All | All | All |
| Application | Wsn | Links | 4.0.19 | All | All | All |
| Application | Wsn | Links | 4.0.2 | All | All | All |
| Application | Wsn | Links | 4.0.20 | All | All | All |
| Application | Wsn | Links | 4.0.21 | All | All | All |
| Application | Wsn | Links | 4.0.22 | All | All | All |
| Application | Wsn | Links | 4.0.23 | All | All | All |
| Application | Wsn | Links | 4.0.24 | All | All | All |
| Application | Wsn | Links | 4.0.25 | All | All | All |
| Application | Wsn | Links | 4.0.26 | All | All | All |
| Application | Wsn | Links | 4.0.27 | All | All | All |
| Application | Wsn | Links | 4.0.28 | All | All | All |
| Application | Wsn | Links | 4.0.29 | All | All | All |
| Application | Wsn | Links | 4.0.3 | All | All | All |
| Application | Wsn | Links | 4.0.30 | All | All | All |
| Application | Wsn | Links | 4.0.31 | All | All | All |
| Application | Wsn | Links | 4.0.32 | All | All | All |
| Application | Wsn | Links | 4.0.33 | All | All | All |
| Application | Wsn | Links | 4.0.34 | All | All | All |
| Application | Wsn | Links | 4.0.35 | All | All | All |
| Application | Wsn | Links | 4.0.36 | All | All | All |
| Application | Wsn | Links | 4.0.37 | All | All | All |
| Application | Wsn | Links | 4.0.38 | All | All | All |
| Application | Wsn | Links | 4.0.39 | All | All | All |
| Application | Wsn | Links | 4.0.4 | All | All | All |
| Application | Wsn | Links | 4.0.40 | All | All | All |
| Application | Wsn | Links | 4.0.41 | All | All | All |
| Application | Wsn | Links | 4.0.5 | All | All | All |
| Application | Wsn | Links | 4.0.6 | All | All | All |
| Application | Wsn | Links | 4.0.7 | All | All | All |
| Application | Wsn | Links | 4.0.8 | All | All | All |
| Application | Wsn | Links | 4.0.9 | All | All | All |
| Application | Wsn | Links | 4.1.0 | All | All | All |
| Application | Wsn | Links | 4.1.1 | All | All | All |
| Application | Wsn | Links | 4.1.10 | All | All | All |
| Application | Wsn | Links | 4.1.11 | All | All | All |
| Application | Wsn | Links | 4.1.12 | All | All | All |
| Application | Wsn | Links | 4.1.13 | All | All | All |
| Application | Wsn | Links | 4.1.14 | All | All | All |
| Application | Wsn | Links | 4.1.15 | All | All | All |
| Application | Wsn | Links | 4.1.16 | All | All | All |
| Application | Wsn | Links | 4.1.17 | All | All | All |
| Application | Wsn | Links | 4.1.18 | All | All | All |
| Application | Wsn | Links | 4.1.19 | All | All | All |
| Application | Wsn | Links | 4.1.2 | All | All | All |
| Application | Wsn | Links | 4.1.20 | All | All | All |
| Application | Wsn | Links | 4.1.21 | All | All | All |
| Application | Wsn | Links | 4.1.22 | All | All | All |
| Application | Wsn | Links | 4.1.23 | All | All | All |
| Application | Wsn | Links | 4.1.24 | All | All | All |
| Application | Wsn | Links | 4.1.25 | All | All | All |
| Application | Wsn | Links | 4.1.26 | All | All | All |
| Application | Wsn | Links | 4.1.27 | All | All | All |
| Application | Wsn | Links | 4.1.28 | All | All | All |
| Application | Wsn | Links | 4.1.29 | All | All | All |
| Application | Wsn | Links | 4.1.3 | All | All | All |
| Application | Wsn | Links | 4.1.30 | All | All | All |
| Application | Wsn | Links | 4.1.31 | All | All | All |
| Application | Wsn | Links | 4.1.32 | All | All | All |
| Application | Wsn | Links | 4.1.33 | All | All | All |
| Application | Wsn | Links | 4.1.34 | All | All | All |
| Application | Wsn | Links | 4.1.35 | All | All | All |
| Application | Wsn | Links | 4.1.36 | All | All | All |
| Application | Wsn | Links | 4.1.37 | All | All | All |
| Application | Wsn | Links | 4.1.38 | All | All | All |
| Application | Wsn | Links | 4.1.39 | All | All | All |
| Application | Wsn | Links | 4.1.4 | All | All | All |
| Application | Wsn | Links | 4.1.40 | All | All | All |
| Application | Wsn | Links | 4.1.41 | All | All | All |
| Application | Wsn | Links | 4.1.42 | All | All | All |
| Application | Wsn | Links | 4.1.43 | All | All | All |
| Application | Wsn | Links | 4.1.44 | All | All | All |
| Application | Wsn | Links | 4.1.5 | All | All | All |
| Application | Wsn | Links | 4.1.6 | All | All | All |
| Application | Wsn | Links | 4.1.7 | All | All | All |
| Application | Wsn | Links | 4.1.8 | All | All | All |
| Application | Wsn | Links | 4.1.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Wsn (Multiple Products) - Local File Inclusion / Code Execution - PHP webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| SecurityReason - Multiple Wsn Products (LFI) Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| WSN Products "TID" Local File Inclusion - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.