5
CVE-2007-4092
- EPSS 2.69%
- Veröffentlicht 30.07.2007 20:17:00
- Zuletzt bearbeitet 16.06.2026 22:43:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary directories, and possibly download arbitrary photos, via a .. (dot dot) in the dir parameter.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.69% | 0.839 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://lostmon.blogspot.com/2007/07/ifoto-traversal-folder-enumeration.html
http://secunia.com/advisories/26186
http://www.securityfocus.com/archive/1/497027/100/0/threaded
http://www.securityfocus.com/archive/1/497113/100/0/threaded
http://www.securityfocus.com/bid/25065