Unrated severityNVD Advisory· Published Sep 4, 2009· Updated Apr 23, 2026
CVE-2008-7163
CVE-2008-7163
Description
Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the sine[config][index_main] parameter.
Affected products
8cpe:2.3:a:sinecms:sinecms:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:sinecms:sinecms:*:*:*:*:*:*:*:*range: <=2.3.5
- cpe:2.3:a:sinecms:sinecms:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:sinecms:sinecms:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:sinecms:sinecms:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:sinecms:sinecms:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:sinecms:sinecms:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:sinecms:sinecms:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:sinecms:sinecms:2.3.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- osvdb.org/40084nvdExploit
- www.securityfocus.com/bid/27156nvdExploit
- secunia.com/advisories/28305nvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/39446nvd
- www.exploit-db.com/exploits/4854nvd
News mentions
0No linked articles in our index yet.