7.8
CVSSv2

CVE-2007-3529

Published: 03/07/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

videos.php in PHPDirector 0.21 and previous versions allows remote malicious users to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

phpdirector phpdirector

Exploits

PHPDirector <= 021 (SQL injection/Upload SHELL) Remote Vulnerabilities WEB APP: PHPDirector 021 SITE: wwwphpdirectorcouk/site/ DORK: "Powered by PHP Director" AUTHOR: Kw3rLn [ teh_lost_byte[at]YaHoO[d0t]Com ] * Romanian Security Team [Ethical Hacking] - hTTp://RSTZONEnET DESCRIPTION: - SQL injection in $id of videosphp ...