Описание
Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a ..\ (dot dot backslash) in the config parameter.
Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a ..\ (dot dot backslash) in the config parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2007-6471
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39063
- http://secunia.com/advisories/28111
- http://securityreason.com/securityalert/3466
- http://www.securityfocus.com/archive/1/485149/100/0/threaded
- http://www.securityfocus.com/bid/26881
- http://www.vupen.com/english/advisories/2007/4231
Связанные уязвимости
nvd
около 18 лет назад
Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a ..\ (dot dot backslash) in the config parameter.