← Vulnerability feed

Vulnerability record · CVE-2008-2650 · published 10 June 2008

CVE-2008-2650: Cmsimple path traversal vulnerability

Cmsimple · Cmsimple

Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number.

6.8 CVSS 2.0 Medium EPSS 19% · top 2.8% CWE-22 · Path traversal
6.8CVSS 2.0 base score
19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2650 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43741Cmsimple path traversal vulnerabilityCMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading…EPSS 4.7%9.1CVE-2024-57548Cmsimple incorrect default permissions vulnerabilityCMSimple 5.16 allows the user to edit log.php file via print page.EPSS 0.47%8.6CVE-2021-47734Cmsimple php remote file inclusion vulnerabilityCMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute ar…EPSS 0.78%8.6CVE-2021-47735Cmsimple code injection vulnerabilityCMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template…EPSS 0.88%8.6CVE-2024-58280Cmsimple vulnerabilityCMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PH…EPSS 0.94%7.5CVE-2024-57547Cmsimple incorrect permission assignment vulnerabilityInsecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functional…EPSS 0.57%7.5CVE-2024-57549Cmsimple path traversal vulnerabilityCMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.EPSS 0.66%7.5CVE-2024-57546Cmsimple vulnerabilityAn issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2008-2650), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.