Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6581

Опубликовано: 28 дек. 2007
Источник: nvd
CVSS2: 6.4
EPSS Средний

Описание

Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang parameter to (1) header_album.php, (2) header_blog.php, or (3) header_group.php; or (4) admin_header_album.php, (5) admin_header_blog.php, or (6) admin_header_group.php in admin/.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:social_engine:social_engine:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.10619
Средний

6.4 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
почти 4 года назад

Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang parameter to (1) header_album.php, (2) header_blog.php, or (3) header_group.php; or (4) admin_header_album.php, (5) admin_header_blog.php, or (6) admin_header_group.php in admin/.

EPSS

Процентиль: 93%
0.10619
Средний

6.4 Medium

CVSS2

Дефекты

CWE-22