CVE-2008-7064
Estado: ModificadaAlta (7.5)—
Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a "\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for "/" (forward slash), as demonstrated by uploading and including PHP code in an avatar file.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.19%
- Percentil entre todas las CVEs puntuadas: 88
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- http://osvdb.org/50143
- http://secunia.com/advisories/32823
- http://secunia.com/advisories/38670
- http://www.qsfportal.com/index.php?a=newspost&t=191
- http://www.securityfocus.com/bid/32452
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46823
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46828
- https://www.exploit-db.com/exploits/7217
- http://osvdb.org/50143
- http://secunia.com/advisories/32823
- http://secunia.com/advisories/38670
- http://www.qsfportal.com/index.php?a=newspost&t=191
- http://www.securityfocus.com/bid/32452
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46823
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46828
- https://www.exploit-db.com/exploits/7217
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-7064",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-08-25T10:30:00.280",
"references": [
{
"url": "http://osvdb.org/50143",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/32823",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/38670",
"source": "cve@mitre.org"
},
{
"url": "http://www.qsfportal.com/index.php?a=newspost&t=191",
"tags": [
"URL Repurposed"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/32452",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46823",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46828",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/7217",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/50143",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/32823",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/38670",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.qsfportal.com/index.php?a=newspost&t=191",
"tags": [
"URL Repurposed"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/32452",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46823",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46828",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/7217",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a \"\\\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for \"/\" (forward slash), as demonstrated by uploading and including PHP code in an avatar file."
},
{
"lang": "es",
"value": "La vulnerabilidad de salto del directorio en la función get_lang en el archivo global.php en Quicksilver Forums versión 1.4.2 y anteriores, como es usado en QSF Portal anterior a versión 1.4.5, cuando es ejecutado en Windows, permite a los atacantes remotos incluir y ejecutar archivos locales arbitrarios por medio de un \"\\\" (barra diagonal invertida) en el parámetro lang en archivo index.php, que omite un mecanismo de protección que solo comprueba \"/\" (barra diagonal), como es demostrado al cargar e incluir el código PHP en un archivo avatar."
}
],
"lastModified": "2026-06-16T23:03:31.550",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:quicksilver_forums:quicksilver_forums:1.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F47737FE-E985-4C4A-86C6-A13EC17CE42C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}