5
CVSSv2

CVE-2005-3948

Published: 01/12/2005 Updated: 03/10/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and previous versions allows remote malicious users to read arbitrary files via the (1) cmd and (2) var1 parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

phpalbum.net phpalbum

Exploits

---------------------------------------------------------------- PHP Photo Album <= (04116) Multiple Disclosure Vulnerabilities ---------------------------------------------------------------- # Exploit Title: PHP Photo Album <= (04116) Multiple Disclosure Vulnerabilities # Google Dork: inurl:mainphp?cmd=imageview&var1= # Applicat ...
source: wwwsecurityfocuscom/bid/15651/info phpAlbum is prone to a local file-include vulnerability An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer with the privileges of the webserver process Note that this issue may also be leveraged to read arbitrary files on an a ...