Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2008-1730

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ARWScripts Gallery Script Lite (又称gallery-script-lite或Free Photo Gallery Site Script)中的download.html存在目录遍历漏洞,比如20080411,它允许远程攻击者借助路径参数中的目录遍历序列,读取任意的本地文件。

AI Predicted 7.5 Difficulty: Trivial EPSS 2.92% · P86

Public Exploits 1

ExploitDB · 1 EDB-5419 [webapps]
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2008-1730

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Directory traversal vulnerability in download.html in ARWScripts Gallery Script Lite (aka gallery-script-lite or Free Photo Gallery Site Script), as of 20080411, allows remote attackers to read arbitrary local files via directory traversal sequences in the path parameter.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
ARWScripts Gallery Script Lite 'download.html' 目录遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ARWScripts Gallery Script Lite (又称gallery-script-lite或Free Photo Gallery Site Script)中的download.html存在目录遍历漏洞,比如20080411,它允许远程攻击者借助路径参数中的目录遍历序列,读取任意的本地文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2008-1730

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-1730

登录查看更多情报信息。

Vendor Advisories for CVE-2008-1730 (4)

Exploits & Public PoCs for CVE-2008-1730 (1)

Same Patch Batch · n/a · 2008-04-11 · 20 CVEs total

CVE-2008-1726 MyKnowledgeQuest KnowledgeQuest 多个SQL注入漏洞
CVE-2008-1704 TIBCO多个产品远程溢出漏洞
CVE-2008-1703 TIBCO多个产品远程溢出漏洞
CVE-2008-1658 PolicyKit Grant Helper 格式化字符串漏洞
CVE-2008-1733 Pragmatic Utopia PU Arcade index.php SQL注入漏洞
CVE-2008-1732 Prediction Football 'showpredictionsformatch.php' SQL注入漏洞
CVE-2008-1731 Drupal Simple Access Module 安全绕过漏洞
CVE-2008-1729 Drupal 安全漏洞
CVE-2008-1728 Openfire 未明远程拒绝服务漏洞
CVE-2008-1727 Knowledgequest 'admincheck.php' 身份验证漏洞
CVE-2008-1750 LiveCart 目录脚本id参数 SQL注入漏洞
CVE-2008-1725 IBiz E-Banking Integrator ActiveX控件WriteOFXDataFile()不安全调用漏洞
CVE-2008-1724 Tumbleweed SecureTransport 'vcst_eu.dll' ActiveX 控件 远程缓冲区溢出漏洞
CVE-2008-1756 Sun N1 Grid Engine 'Qmaster' Daemon 本地拒绝服务漏洞
CVE-2008-1755 World of Phaos R4000 'showSource.php'目录遍历漏洞
CVE-2008-1754 Symantec Altiris Deployment Solution AClient口令泄露漏洞
CVE-2008-1753 Alkacon OpenCms 'sessions.jsp' 多个跨站脚本攻击漏洞
CVE-2008-1752 Ezradius 设计错误漏洞
CVE-2008-1751 KSEMAIL 'index.php' 多个目录遍历漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-1730

No comments yet


Leave a comment