Skip to main content
定价企业版
首页/漏洞/EDB-4794
EDB-4794webappsphp已验证

XZero Community Classifieds 4.95.11 - Local File Inclusion / SQL Injection

Kw3[R]Ln12/26/2007
在Exploit-DB查看在GitLab查看源代码

AI分析AI驱动

漏洞利用代码

Exploit code not available in database

在GitLab查看源代码

相关CVE (2)

CVE-2007-6567

NONE

Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagenam

Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagenam...

12/28/2007CWE-22

CVE-2007-6566

NONE

SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php.

SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php.

12/28/2007CWE-89

漏洞利用信息

EDB ID
4794
类型
webapps
平台
php
已验证
是
发布日期
2007-12-26

关联的CVE

CVE-2007-6567CVE-2007-6566

快速操作

下载原始文件在Google搜索
免责声明:此漏洞利用代码仅供教育和授权的安全研究目的使用。请负责任地使用,并仅在您有权测试的系统上使用。