9.4
CVSSv2

CVE-2007-1140

Published: 02/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9.4 | Impact Score: 9.2 | Exploitability Score: 10
VMScore: 945
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:N

Vulnerability Summary

Directory traversal vulnerability in edit.php in pheap allows remote malicious users to read and modify arbitrary files via a .. (dot dot) in the filename parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

barekoncept pheap -

Exploits

source: wwwsecurityfocuscom/bid/22670/info Pheap is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability to retrieve and edit the contents of arbitrary files from the vulnerable system in the context of the affected application wwwexa ...