5
CVSSv2

CVE-2007-1138

Published: 02/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote malicious users to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cromosoft simple plantilla php -

Exploits

source: wwwsecurityfocuscom/bid/22669/info Simple Plantilla PHP is prone to multiple input-validation issues, including a local file-include vulnerability and an arbitrary file-upload vulnerability Attackers can exploit the local file-include vulnerability using directory-traversal strings to execute local script code in the context of ...