CVE-2008-0158

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
09/01/2008
Last modified:
09/04/2025

Description

Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:shop-script:shop-script:2.0:*:*:*:*:*:*:*