{"api_version":"1","generated_at":"2026-07-23T11:30:34+00:00","cve":"CVE-2008-7064","urls":{"html":"https://cve.report/CVE-2008-7064","api":"https://cve.report/api/cve/CVE-2008-7064.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-7064","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-7064"},"summary":{"title":"CVE-2008-7064","description":"Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a \"\\\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for \"/\" (forward slash), as demonstrated by uploading and including PHP code in an avatar file.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-08-25 10:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-22","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46828","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46828","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46823","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46823","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/50143","name":"http://osvdb.org/50143","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.qsfportal.com/index.php?a=newspost&t=191","name":"http://www.qsfportal.com/index.php?a=newspost&t=191","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["URL Repurposed"],"title":"港京印刷图源总汇,六合特码暴料,990990藏宝阁香港开马,苗栗县清域阳光商贸有限公司-首页","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/32452","name":"http://www.securityfocus.com/bid/32452","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Quicksilver Forums Local File Include and Arbitrary File Upload Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/32823","name":"http://secunia.com/advisories/32823","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/7217","name":"https://www.exploit-db.com/exploits/7217","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Quicksilver Forums <= 1.4.2 RCE Exploit (windows only)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38670","name":"http://secunia.com/advisories/38670","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA38670 - QSF Portal &quot;lang&quot; File Inclusion Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-7064","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-7064","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"7064","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"quicksilver_forums","cpe5":"quicksilver_forums","cpe6":"1.4.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T11:56:12.929Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"7217","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/7217"},{"name":"quicksilverforums-avatar-file-upload(46828)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46828"},{"name":"32823","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32823"},{"name":"quicksilverforums-index-file-include(46823)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46823"},{"name":"38670","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38670"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.qsfportal.com/index.php?a=newspost&t=191"},{"name":"50143","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/50143"},{"name":"32452","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/32452"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-11-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a \"\\\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for \"/\" (forward slash), as demonstrated by uploading and including PHP code in an avatar file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"7217","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/7217"},{"name":"quicksilverforums-avatar-file-upload(46828)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46828"},{"name":"32823","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32823"},{"name":"quicksilverforums-index-file-include(46823)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46823"},{"name":"38670","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38670"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.qsfportal.com/index.php?a=newspost&t=191"},{"name":"50143","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/50143"},{"name":"32452","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/32452"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-7064","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a \"\\\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for \"/\" (forward slash), as demonstrated by uploading and including PHP code in an avatar file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"7217","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/7217"},{"name":"quicksilverforums-avatar-file-upload(46828)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46828"},{"name":"32823","refsource":"SECUNIA","url":"http://secunia.com/advisories/32823"},{"name":"quicksilverforums-index-file-include(46823)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46823"},{"name":"38670","refsource":"SECUNIA","url":"http://secunia.com/advisories/38670"},{"name":"http://www.qsfportal.com/index.php?a=newspost&t=191","refsource":"CONFIRM","url":"http://www.qsfportal.com/index.php?a=newspost&t=191"},{"name":"50143","refsource":"OSVDB","url":"http://osvdb.org/50143"},{"name":"32452","refsource":"BID","url":"http://www.securityfocus.com/bid/32452"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-7064","datePublished":"2009-08-25T10:00:00.000Z","dateReserved":"2009-08-24T00:00:00.000Z","dateUpdated":"2024-08-07T11:56:12.929Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-08-25 10:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-22","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:quicksilver_forums:quicksilver_forums:1.4.2:*:*:*:*:*:*:*","matchCriteriaId":"F47737FE-E985-4C4A-86C6-A13EC17CE42C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"7064","Ordinal":"1","Title":"CVE-2008-7064","CVE":"CVE-2008-7064","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"7064","Ordinal":"1","NoteData":"Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a \"\\\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for \"/\" (forward slash), as demonstrated by uploading and including PHP code in an avatar file.","Type":"Description","Title":"CVE-2008-7064"},{"CveYear":"2008","CveId":"7064","Ordinal":"2","NoteData":"2009-08-25","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"7064","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}