7.5
CVSSv2

CVE-2008-7240

Published: 17/09/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote malicious users to include and execute arbitrary local files via the template parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

linuxwebshop php user base 1.3

Exploits

##################################################### #Author : BeyazKurt - Bey4zKurt@GmailCom # #Script : php User Base (13b) #Risk : Local File Include #Download : sourceforgenet/project/showfilesphp?group_id=200632 # #File : include/unverifiedincphp # #Code : # # <?php # include("/templates/$template/globalincphp"); # ?> ...