VulnerabilityModified
CVE-2007-0700
Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a ..
MEDIUM 5.0EPSS 3.44%
Does this matter?
Lower severity and a low EPSS score (3.44%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this issue was later reported for 2.5.1.1.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.44% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- portail web php/portail web php
- Source
- cve@mitre.org
References
- http://osvdb.org/33634
- http://www.attrition.org/pipermail/vim/2007-February/001269.htmlExploit
- http://www.attrition.org/pipermail/vim/2007-February/001280.html
- http://www.attrition.org/pipermail/vim/2007-February/001281.html
- http://www.securityfocus.com/archive/1/458805/100/0/threaded
- http://www.securityfocus.com/bid/22361Exploit
- http://www.securityfocus.com/bid/27962
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32115
- https://www.exploit-db.com/exploits/5182
- http://osvdb.org/33634
- http://www.attrition.org/pipermail/vim/2007-February/001269.htmlExploit
- http://www.attrition.org/pipermail/vim/2007-February/001280.html
- http://www.attrition.org/pipermail/vim/2007-February/001281.html
- http://www.securityfocus.com/archive/1/458805/100/0/threaded
- http://www.securityfocus.com/bid/22361Exploit
- http://www.securityfocus.com/bid/27962
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32115
- https://www.exploit-db.com/exploits/5182
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.