CVE-2006-7080 Information

Description

Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ..\ sequences in the old_avatar parameter.

Reference

http://www.securityfocus.com/bid/20161 https://exchange.xforce.ibmcloud.com/vulnerabilities/29130 https://www.exploit-db.com/exploits/2415

Share on: