Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4536

Опубликовано: 25 авг. 2007
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:torrenttrader:torrenttrader:*:*:*:*:*:*:*:*
Версия до 1.07 (включая)

EPSS

Процентиль: 20%
0.00063
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.

EPSS

Процентиль: 20%
0.00063
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other