Unrated severityNVD Advisory· Published Apr 1, 2008· Updated Apr 23, 2026
CVE-2008-1606
CVE-2008-1606
Description
Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot dot) in the file parameter to manager/getImportFileRedirect.jsp, (2) upload arbitrary files via a "..\" (dot dot backslash) in the file parameter to importData.jsp, and (3) list directory contents via a .. (dot dot) in the dir parameter to manager/fileManager.jsp.
Affected products
2cpe:2.3:a:elastic_path:elastic_path:4.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:elastic_path:elastic_path:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:elastic_path:elastic_path:4.1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/29496nvdPatchVendor Advisory
- www.mwrinfosecurity.com/publications/mwri_elastic-path-arbitrary-file-system-access_2008-02-22.pdfnvdExploit
- developer.elasticpath.com/entry%21default.jspanvd
- weblog.nomejortu.comnvd
- www.securityfocus.com/bid/28352nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/41356nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/41364nvd
News mentions
0No linked articles in our index yet.