5
CVSSv2

CVE-2011-5219

Published: 25/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the filename parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mpdf1 mpdf

mpdf1 mpdf 5.2

Exploits

# Exploit Title: mPDF <= 53 File Disclosure # Google Dork: Please no dork # Date: 16th December 2011 # Author: ZadYree # Software Link: wwwmpdf1com/mpdf/download # Version: 53 and prior # Tested on: Multiple # CVE : N/A #!/usr/bin/perl -U =head1 TITLE mPDF <= 53 File Disclosure Exploit (0day) =head2 SYNOPSIS -- examples/show_c ...