5

CVE-2007-0620

Exploit
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vlad LeontFd Script Version1.3
Vlad LeontFd Script Version1.3.1
Vlad LeontFd Script Version1.3.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.5% 0.876
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/33001
http://secunia.com/advisories/23947
Vendor Advisory
http://securityreason.com/securityalert/2197
http://www.securityfocus.com/archive/1/458231/100/0/threaded
http://www.securityfocus.com/bid/22265
Exploit
http://www.vupen.com/english/advisories/2007/0383
https://exchange.xforce.ibmcloud.com/vulnerabilities/31915