AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-5518

HIGH · CVSS 9.4 EPSS 35.93% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-04-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2008-5518
Severity
HIGH
CVSS
9.4
EPSS
35.93%
Windows Apache

Original NVD Description

Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet); the (5) createDB parameter to console/portal/Embedded DB/DB Manager (aka the Embedded DB/DB Manager portlet); or the (6) filename parameter to the createKeystore script in the Security/Keystores portlet.