CVE-2008-4181
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.8%
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/6461⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.