VYPR
Unrated severityNVD Advisory· Published Sep 29, 2008· Updated Apr 23, 2026

CVE-2008-4319

CVE-2008-4319

Description

fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.

Affected products

6
  • cpe:2.3:a:libra_file_manager:php_filemanager:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:libra_file_manager:php_filemanager:*:*:*:*:*:*:*:*range: <=1.18
    • cpe:2.3:a:libra_file_manager:php_filemanager:1.00:*:*:*:*:*:*:*
    • cpe:2.3:a:libra_file_manager:php_filemanager:1.03:*:*:*:*:*:*:*
    • cpe:2.3:a:libra_file_manager:php_filemanager:1.05:*:*:*:*:*:*:*
    • cpe:2.3:a:libra_file_manager:php_filemanager:1.08:*:*:*:*:*:*:*
    • cpe:2.3:a:libra_file_manager:php_filemanager:1.17:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.