5.1
CVSSv2

CVE-2008-7055

Published: 24/08/2009 Updated: 11/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

module.php in ezContents 2.0.3 allows remote malicious users to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot dot slash) sequences in the link parameter, which is not properly filtered using the str_replace function.

Vulnerable Product Search on Vulmon Subscribe to Product

visualshapers ezcontents 2.0.3

Exploits

Digital Security Research Group [DSecRG] Advisory #DSECRG-08-038 Application: ezContents CMS Versions Affected: 203 Application URL: wwwezcontentsorg/ Vendor URL: wwwvisualshaperscom/ Bug: Multiple Local File Include Exploits: ...