S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2008-6668 Scanner

CVE-2008-6668 scanner - Directory Traversal vulnerability in nweb2fax

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2008-6668
5.0
CVSS

Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename parameter to viewrq.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Nweb2fax is a software application designed to convert any printable file into a fax document. This software product is a perfect fit for those who want to send faxes over the internet. Nweb2fax 0.2.7 and previous versions were recently detected to have multiple directory traversal vulnerabilities that can jeopardize the security of the product. 

CVE-2008-6668 vulnerability was spotted in this product, which allows remote attackers to read arbitrary files via a ".." in the id parameter of comm.php and the var_filename parameter of viewrq.php. The vulnerability can be exploited by an attacker to gain access to sensitive files and metadata without proper authentication. This vulnerability flaw can expose user data to malicious entities.

Exploiting this vulnerability can lead to a potential data breach and identity theft. It could allow threat actors to steal sensitive data files that can result in reputational damage to an organization. This vulnerability can also create a gateway for attackers to take control of other systems in an enterprise and use its resources to launch further cyberattacks.

At s4e.io, we offer cutting-edge security features that ensure the safety and protection of your digital assets. By leveraging the latest technology and its innovative process, we guarantee that you will receive expert analysis of vulnerabilities and their possible impact on your organization. Our team of skilled security professionals continuously monitor your assets and are always ready to provide you with proactive remedies. Get in touch with us today and learn more about how we can help you secure your digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Update to the latest version of nweb2fax
  • Implement proper input validation and sanitization to prevent directory traversal attacks
  • Limit access to the web application to trusted users
  • Disable directory listing in the web application to prevent unauthorized browsing of directories

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2008-6668 scanner - Directory Traversal vulnerability in nweb2fax | S4E