CVE-2007-0620 Information
Feb 14, 2021
cve
Description
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions including .php via a relative pathname in the fname parameter as demonstrated by downloading config.php.
Reference
http://osvdb.org/33001 http://secunia.com/advisories/23947 http://securityreason.com/securityalert/2197 http://www.securityfocus.com/archive/1/458231/100/0/threaded http://www.securityfocus.com/bid/22265 http://www.vupen.com/english/advisories/2007/0383 https://exchange.xforce.ibmcloud.com/vulnerabilities/31915
Share on: