CVE-2008-6361
Status: ModifiedMedium (6.8)—💥 Exploit
Directory traversal vulnerability in index.php in InSun Feed CMS 1.7.3 19Beta allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Base score: 6.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.85%
- Percentile among all scored CVEs: 78
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Feed CMS 1.07.03.19b - 'lang' Local File Inclusion (12/11/2008)
Affected technologies (1)
CWEs
- CWE-22
References
- http://www.securityfocus.com/bid/32783
- http://www.securityfocus.com/bid/32783/exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47276
- https://www.exploit-db.com/exploits/7422
- http://www.securityfocus.com/bid/32783
- http://www.securityfocus.com/bid/32783/exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47276
- https://www.exploit-db.com/exploits/7422
Raw JSON (NVD)
Show
{
"id": "CVE-2008-6361",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-03-02T16:30:00.610",
"references": [
{
"url": "http://www.securityfocus.com/bid/32783",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/32783/exploit",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47276",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/7422",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/32783",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/32783/exploit",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47276",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/7422",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Directory traversal vulnerability in index.php in InSun Feed CMS 1.7.3 19Beta allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter."
},
{
"lang": "es",
"value": "Vulnerabilidad de salto de directorio en archivo index.php en InSun Feed CMS versión 1.7.3 19Beta, permite a los atacantes remotos incluir y ejecutar archivos locales arbitrarios por medio de secuencias de salto de directorio en el parámetro lang."
}
],
"lastModified": "2026-06-16T23:02:05.477",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:insun_podcast:feedcms:1.7.3_19beta:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC6D379F-48FA-43A2-AFCC-D1AA63784B55"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}