Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5732

Опубликовано: 30 окт. 2007
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Directory traversal vulnerability in downloadfile.php in eLouai's Force Download of media files script, as available on 20071030 and earlier, allows remote attackers to read arbitrary files via the file parameter. NOTE: this issue only occurs in environments where the system administrator has not followed the vendor recommendations that this product should only be used internally.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elouai:force_download:*:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00095
Низкий

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
почти 4 года назад

Directory traversal vulnerability in downloadfile.php in eLouai's Force Download of media files script, as available on 20071030 and earlier, allows remote attackers to read arbitrary files via the file parameter. NOTE: this issue only occurs in environments where the system administrator has not followed the vendor recommendations that this product should only be used internally.

EPSS

Процентиль: 27%
0.00095
Низкий

5 Medium

CVSS2

Дефекты

CWE-22