5
CVSSv2

CVE-2011-4807

Published: 14/12/2011 Updated: 10/02/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the var1 parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpalbum phpalbum 0.4.1.15

phpalbum phpalbum 0.4.1-14

phpalbum phpalbum 0.3.1

phpalbum phpalbum 0.3.0

phpalbum phpalbum 0.4.1.14

phpalbum phpalbum

phpalbum phpalbum 0.2.3

phpalbum phpalbum 0.2.2

phpalbum phpalbum 0.2.1

phpalbum phpalbum 0.3.2

phpalbum phpalbum 0.2.4

Exploits

---------------------------------------------------------------- PHP Photo Album <= (04116) Multiple Disclosure Vulnerabilities ---------------------------------------------------------------- # Exploit Title: PHP Photo Album <= (04116) Multiple Disclosure Vulnerabilities # Google Dork: inurl:mainphp?cmd=imageview&var1= # Applicat ...