5
CVSSv2

CVE-2008-2215

Published: 14/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote malicious users to read arbitrary files via a .. (dot dot) in the filename parameter to (1) src/yopy_sync.php and (2) system-logger/print_logs.php.

Vulnerable Product Search on Vulmon Subscribe to Product

pbcs project-based calendaring system 0.7.1-1

Exploits

Project Based Calendaring System (PBCS) Version 071 Multiple Vulnerabilities Script: wwwpbcsorg/pbcs_downloadphp Poc : Hi str0ke Thanx To Posted but I Want Add Some Vulns In This Script 1- remote file upload localhost/pbcs-071-1/src/yopy_uploadphp after upload you can get you file on localhost/pbcs-071-1//tmp/uploads ...