CVE-2008-6604 describes a critical directory traversal vulnerability in PicoFlat CMS version 0.5.9, allowing remote attackers to include and execute arbitrary local files. This flaw, distinct from CVE-2007-5390, is exploited by manipulating the "pagina" parameter with ".." sequences. With a CVSS score of 10.0 and a FAUCET Risk Score of 95/100, this vulnerability presents a severe risk, enabling complete compromise of confidentiality, integrity, and availability without authentication. While not listed in CISA's KEV catalog or having widespread community discussion, an ExploitDB entry (EDB-5690) confirms the existence of exploit code for Windows systems, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.5.9CPE matchmatch criteria | cpe:2.3:a:picoflat:picoflat_cms:0.5.9:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.