4.3
CVSSv2

CVE-2007-1539

Published: 20/03/2007 Updated: 19/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote malicious users to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.

Vulnerable Product Search on Vulmon Subscribe to Product

pragmamx landkarten 2.1

Exploits

#!Perl # #pragmaMX Landkartenmodule 21 Local File Inclusion Exploit # #Vendor: wwwpragmamxorg/Downloads-op-getit-lid-599-noJpC-html # #Vulnerable Code: require_once("modules/$module_name/inc/confphp"); # #Coded by bd0rk || SOH-Crew # #Greetz: str0ke, Diddi, seduce, TheJT, broken-error # use IO::Socket; use LWP::Simple; #ripped @apach ...