5
CVSSv2

CVE-2007-2369

Published: 30/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and previous versions, when PHP prior to 4.3.0 is used, allows remote malicious users to read arbitrary files via a .. (dot dot) in the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

php php

webspell webspell

Exploits

# WebSPELL <= 40102 (picturephp) Remote File Disclosure Vulnerability # Discovered by: Trex # Visit: wwwTrex-Onlinenet / wwwUnderGroundag # Comment: Happy easter! # # ___ ___ # / \ / \ ___________________________ # / / \_/ \ \ / \ # \__/\ /\__/ / GIVE ME A CARROT OR I WILL \ # ...