CVE-2007-2369 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier when PHP before 4.3.0 is used allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
Reference
http://osvdb.org/34638 http://www.vupen.com/english/advisories/2007/1274 https://www.exploit-db.com/exploits/3673
Share on: