Skip to main content
定价企业版
首页/漏洞/EDB-2415
EDB-2415webappsphp已验证

exV2 < 2.0.4.3 - 'extract()' Remote Command Execution

rgod9/22/2006
在Exploit-DB查看在GitLab查看源代码

AI分析AI驱动

漏洞利用代码

Exploit code not available in database

在GitLab查看源代码

相关CVE (2)

CVE-2006-7080

NONE

Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.

Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.

3/2/2007

CVE-2006-7079

9.8CRITICAL

Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute

Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute ...

3/2/2007CWE-22, CWE-913

漏洞利用信息

EDB ID
2415
类型
webapps
平台
php
已验证
是
发布日期
2006-09-22

关联的CVE

CVE-2006-7080CVE-2006-7079

快速操作

下载原始文件在Google搜索
免责声明:此漏洞利用代码仅供教育和授权的安全研究目的使用。请负责任地使用,并仅在您有权测试的系统上使用。