Skip to main content
PreçosEnterprise
Início/Vulnerabilidades/EDB-2415
EDB-2415webappsphpVERIFICADO

exV2 < 2.0.4.3 - 'extract()' Remote Command Execution

rgod9/22/2006
Ver no Exploit-DBVer Fonte no GitLab

Análise IADesenvolvido por IA

Código do Exploit

Exploit code not available in database

Ver Fonte no GitLab

CVEs Relacionados (2)

CVE-2006-7080

NONE

Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.

Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.

3/2/2007

CVE-2006-7079

9.8CRITICAL

Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute

Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute ...

3/2/2007CWE-22, CWE-913

Informações do Exploit

ID EDB
2415
Tipo
webapps
Plataforma
php
Verificado
Sim
Publicado
2006-09-22

CVEs Associados

CVE-2006-7080CVE-2006-7079

Ações Rápidas

Baixar RawPesquisar no Google
Aviso: Este código de exploit é fornecido apenas para fins educacionais e pesquisa de segurança autorizada. Use com responsabilidade.