7.5
CVSSv2

CVE-2007-2304

Published: 26/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to categories.php and other unspecified files.

Vulnerable Product Search on Vulmon Subscribe to Product

qdblog qdblog

Exploits

Quick and Dirty Blog 04 (categoriesphp) Local File Inclusion Vulnerability heanetdlsourceforgenet/sourceforge/qdblog/qdblog-04tarbz2 POC: /categoriesphp?theme=/////////etc/passwd%00 # milw0rmcom [2007-11-03] ...
_ | _ |_ _ _;_/ [_)|(_]\_|[ )(_](_| \net | _| "QDBlog v04 - MULTIPLE VULNERABILITIES" by Omni 1) Infos --------- Date : 2007-04-12 Product : QDBlog Version : v04 - Prior version maybe also be affected Vendor : sourceforgenet/projects/qdblog/ Vendor Stat ...