CVE-2008-6592

high

Description

thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remote attackers to copy, rename, and read arbitrary files via directory traversal sequences in the image parameter with a modified cache_dir parameter containing a %00 (encoded null byte).

References

https://www.exploit-db.com/exploits/5452

https://exchange.xforce.ibmcloud.com/vulnerabilities/49851

http://www.securityfocus.com/bid/28801

http://www.securityfocus.com/archive/1/491064/100/0/threaded

http://secunia.com/advisories/29833

Details

Source: Mitre, NVD

Published: 2009-04-03

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.03888