5
CVSSv2

CVE-2007-6528

Published: 27/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in tiki-listmovies.php in TikiWiki prior to 1.9.9 allows remote malicious users to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

tiki tikiwiki cms\\/groupware 1.9.6

tiki tikiwiki cms\\/groupware 1.9.5

tiki tikiwiki cms\\/groupware 1.9.0

tiki tikiwiki cms\\/groupware

tiki tikiwiki cms\\/groupware 1.9.7

tiki tikiwiki cms\\/groupware 1.9.4

tiki tikiwiki cms\\/groupware 1.9.3

tiki tikiwiki cms\\/groupware 1.6.1

tiki tikiwiki cms\\/groupware 1.9.2

tiki tikiwiki cms\\/groupware 1.9.1

Exploits

TikiWiki < 199 tiki-listmoviesphp Directory Traversal Vulnerability wwwvulnsitecom/tiki-listmoviesphp?movie=//////etc/passwd%001234 # milw0rmcom [2008-01-20] ...