CVE-2007-2659 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obtain script source code via a .. (dot dot) in the directory parameter in a downloadfile action.
Reference
http://osvdb.org/41990 http://www.securityfocus.com/bid/23952 http://www.vupen.com/english/advisories/2007/1799 https://exchange.xforce.ibmcloud.com/vulnerabilities/34255 https://www.exploit-db.com/exploits/3918
Share on: