3.7
CVSSv2

CVE-2008-1696

Published: 08/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 3.7 | Impact Score: 6.4 | Exploitability Score: 1.9
VMScore: 375
Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the prefixdir parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dazphp dazphpnews 0.1-1

Exploits

Script Name : DaZPHP Download : sourceforgenet/project/showfilesphp?group_id=132192 Vul Code[Example] : [site]/[Path]/makepostphp?prefixdir=//////etc/passwd Error : include "/"$prefixdir"/DaZPHPNews-01-1/makepostphp"; Greetz : Kezzap66345 - Str0ke - Dread 35 # milw0rmcom [2008-04-02] ...