5
CVSSv2

CVE-2010-2334

Published: 18/06/2010 Updated: 21/06/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed prior to 20100618, allows remote malicious users to read arbitrary files via a .. (dot dot) in the download parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

yamamah yamamah 1.00

Exploits

|=---------------------------------------------------------------------------=| Yamamah Photo Gallery 100 (downloadphp) Local File Disclosure Vulnerability |=---------------------------------------------------------------------------=| |=------------------------------=[ by mat ]=---------------------------------=| Google dork: "Powered By : Yam ...
# Exploit Title: Yamamah Vulnerability (news) SQL Injection / disclosure Vulnerability # Date: 12-06-2010 # Author: anT!-Tr0J4n #My Home : wwwDev-PoinTcom # Software Link:wwwyamamahorg # Version: 100 # Tested on: Win7/Linux #DorK : N / A ========== Exploit By anT!-Tr0J4n============ =======Yamamah source code disclosure Vulnera ...