6.8
CVSSv2

CVE-2008-4626

Published: 21/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 and possibly other versions up to and including 2.3.3-beta0, when magic_quotes_gpc is disabled, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the album parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

zirkon box yappa-ng 2.3.2

Exploits

[o]------------------------------------------------------------------------------------[x] | Local File Include Vulnerability | [o]------------------------------------------------------------------------------------[o] | Software : yappa-ng Version 232 ...