7.8
CVSSv2

CVE-2007-2285

Published: 26/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote malicious users to read arbitrary files via a .. (dot dot) in the feed parameter. NOTE: analysis by third party researchers indicates that this issue might be platform dependent.

Vulnerable Product Search on Vulmon Subscribe to Product

jack slocum ext js 1.0_alpha1

Exploits

# ext 10 alpha1 (feed-proxyphp) Remote File Disclosure # DScript: yui-extcom/deploy/ext-10-alpha1zip # Discovered by: Alkomandoz Hacker # Homepage: wwwasb-maynet - mohandkocom - sniper-sacom - tryagcom # VCode In /examples/layout/feed-proxyphp ---------------------------------------------------------- header('Content-T ...