Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6552

Опубликовано: 28 дек. 2007
Источник: nvd
CVSS2: 6
EPSS Низкий

Описание

Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/admin_users.php to bypass a protection mechanism against direct request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:auracms:auracms:2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01012
Низкий

6 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
почти 4 года назад

Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/admin_users.php to bypass a protection mechanism against direct request.

EPSS

Процентиль: 77%
0.01012
Низкий

6 Medium

CVSS2

Дефекты

CWE-22