Skip to main content
요금엔터프라이즈
홈/취약점/EDB-2415
EDB-2415webappsphp검증됨

exV2 < 2.0.4.3 - 'extract()' Remote Command Execution

rgod9/22/2006
Exploit-DB에서 보기GitLab에서 소스 보기

AI 분석AI 기반

익스플로잇 코드

Exploit code not available in database

GitLab에서 소스 보기

관련 CVE (2)

CVE-2006-7080

NONE

Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.

Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.

3/2/2007

CVE-2006-7079

9.8CRITICAL

Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute

Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute ...

3/2/2007CWE-22, CWE-913

익스플로잇 정보

EDB ID
2415
유형
webapps
플랫폼
php
검증됨
예
게시됨
2006-09-22

연관된 CVE

CVE-2006-7080CVE-2006-7079

빠른 작업

Raw 다운로드Google에서 검색
면책 조항: 이 익스플로잇 코드는 교육 및 승인된 보안 연구 목적으로만 제공됩니다. 테스트 권한이 있는 시스템에서만 사용하세요.