VulnerabilityModified
CVE-2007-0609
Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a ..
MEDIUM 5.1EPSS 7.51%
Does this matter?
Lower severity and a low EPSS score (7.51%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a .. (dot dot) in a lang cookie, followed by a filename without its .php extension, as demonstrated via a request to index.php.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 7.51% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- advanced guestbook/advanced guestbook
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/25153Vendor Advisory
- http://securityreason.com/securityalert/2662
- http://www.netvigilance.com/advisory0012Vendor Advisory
- http://www.netvigilance.com/advisory0013Vendor Advisory
- http://www.securityfocus.com/archive/1/467937/100/0/threaded
- http://www.securityfocus.com/archive/1/467941/100/0/threaded
- http://www.securityfocus.com/bid/23876Exploit
- http://www.vupen.com/english/advisories/2007/1726
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34152
- http://secunia.com/advisories/25153Vendor Advisory
- http://securityreason.com/securityalert/2662
- http://www.netvigilance.com/advisory0012Vendor Advisory
- http://www.netvigilance.com/advisory0013Vendor Advisory
- http://www.securityfocus.com/archive/1/467937/100/0/threaded
- http://www.securityfocus.com/archive/1/467941/100/0/threaded
- http://www.securityfocus.com/bid/23876Exploit
- http://www.vupen.com/english/advisories/2007/1726
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34152
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.