7.5
CVSSv2

CVE-2007-6184

Published: 30/11/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the act parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

project alumni project alumni 1.0.9

Exploits

project alumni 109 remote file disclosure vulnerability download : sourceforgenet/projects/project-alumni/ vulnerable code on indexphp include($_SERVER['DOCUMENT_ROOT'] "/pages/" $_GET['act'] "pageincphp"); exploit : victim/path/indexphp?act=//////etc/passwd%00 discovered by tomplixsee # milw0rmcom [200 ...