CVE-2007-6397
Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a ..
Does this matter?
Lower severity and a low EPSS score (2.80%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a .. (dot dot) in the username parameter when registering a user account, and (2) read arbitrary PHP files via a .. (dot dot) in (a) the topic parameter in a topic action or (b) the username parameter in a viewprofile action.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.80% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- flat php/board
- Source
- cve@mitre.org
References
- http://osvdb.org/43890
- http://osvdb.org/43891
- http://osvdb.org/43892
- http://www.securityfocus.com/archive/1/484803/100/100/threaded
- http://www.securityfocus.com/bid/26782
- https://www.exploit-db.com/exploits/4705
- http://osvdb.org/43890
- http://osvdb.org/43891
- http://osvdb.org/43892
- http://www.securityfocus.com/archive/1/484803/100/100/threaded
- http://www.securityfocus.com/bid/26782
- https://www.exploit-db.com/exploits/4705
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.