CVE-2008-1409
Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.42%
- Percentil entre todas las CVEs puntuadas: 84
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Exero CMS 1.0.1 - 'theme' Multiple Local File Inclusions (17/3/2008)
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- http://www.securityfocus.com/bid/28273
- http://www.vupen.com/english/advisories/2008/0909/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41238
- https://www.exploit-db.com/exploits/5265
- http://www.securityfocus.com/bid/28273
- http://www.vupen.com/english/advisories/2008/0909/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41238
- https://www.exploit-db.com/exploits/5265
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-1409",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-03-20T10:44:00.000",
"references": [
{
"url": "http://www.securityfocus.com/bid/28273",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0909/references",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41238",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/5265",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/28273",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0909/references",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41238",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/5265",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de salto de directorio en el tema Default de Exero CMS 1.0.1 permite a atacantes remotos incluir y ejecutar ficheros locales de su elección mediante la utilización de secuencias de salto de directorio en el parámetro theme de (1) index.php, (2) editpassword.php, y (3) avatar.php en usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php y (7) profile.php en members/; (8) index.php y (9) fullview.php en news/; y (10) nopermission.php."
}
],
"lastModified": "2026-06-16T22:51:41.020",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:exero:exero_cms:1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB145AE2-B4B1-449B-9A53-C5E2B4EFF571"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}