EDB-4794
webappsphpVERIFIED
XZero Community Classifieds 4.95.11 - Local File Inclusion / SQL Injection
CVE-2007-6567CVE-2007-6566
Kw3[R]Ln12/26/2007
Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter in a page view action.