4.3
CVSSv2

CVE-2006-7080

Published: 02/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and previous versions allows remote malicious users to delete arbitrary files via ".." sequences in the old_avatar parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

exv2 content management system

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? print_r(' ------------------------------------------------------------------------------- exV2 <= 2043 extract() remote commands execution exploit mail: retrog@aliceit site: retrogodaltervistaorg dork: "Powered by eXV2 Vers" ---------------------------------------------------------------- ...