AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-6938

MEDIUM · CVSS 4.3 EPSS 26.48% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-08-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2008-6938
Severity
MEDIUM
CVSS
4.3
EPSS
26.48%
Windows

Original NVD Description

Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.