CVE-2008-4181

CVSS 6.8 - MEDIUM
Description

Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

Affected Products
50 of 133
Vendor Product Version
netenberg fantastico_de_luxe All versions
netenberg fantastico_de_luxe All versions
netenberg fantastico_de_luxe All versions
netenberg fantastico_de_luxe All versions
netenberg fantastico_de_luxe All versions
netenberg fantastico_de_luxe All versions
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.2
netenberg fantastico_de_luxe 2.8.4
netenberg fantastico_de_luxe 2.8.4
netenberg fantastico_de_luxe 2.8.4
netenberg fantastico_de_luxe 2.8.4
netenberg fantastico_de_luxe 2.8.4
netenberg fantastico_de_luxe 2.8.4
netenberg fantastico_de_luxe 2.8.4
netenberg fantastico_de_luxe 2.8.6
netenberg fantastico_de_luxe 2.8.6
netenberg fantastico_de_luxe 2.8.6
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.8
netenberg fantastico_de_luxe 2.8.r1
netenberg fantastico_de_luxe 2.8.r2
netenberg fantastico_de_luxe 2.8.r3
netenberg fantastico_de_luxe 2.8.r4
netenberg fantastico_de_luxe 2.8.r5
netenberg fantastico_de_luxe 2.8.r6
netenberg fantastico_de_luxe 2.8.r7
netenberg fantastico_de_luxe 2.8.r8
netenberg fantastico_de_luxe 2.8.r9
netenberg fantastico_de_luxe 2.8.r10
netenberg fantastico_de_luxe 2.8.r11
netenberg fantastico_de_luxe 2.8.r12
netenberg fantastico_de_luxe 2.8.r13
Showing first 50 of 133 affected products.
Weakness Types
CWE-22
CVE Information
CVE ID:
CVE-2008-4181
Published:
2008-09-23
Modified:
2026-04-23
CVSS Score:
6.8
Severity:
MEDIUM
Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected Vendors
netenberg
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL