CVE-2007-5802 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: this can be leveraged to obtain the path by including a local PHP script with a duplicate function declaration.
Reference
http://osvdb.org/38371 http://secunia.com/advisories/27466 http://securityreason.com/securityalert/3335 http://www.inj3ct-it.org/exploit/syner.txt http://www.securityfocus.com/archive/1/483099/100/0/threaded http://www.securityfocus.com/bid/26289 http://www.vupen.com/english/advisories/2007/3745 https://exchange.xforce.ibmcloud.com/vulnerabilities/38217 https://exchange.xforce.ibmcloud.com/vulnerabilities/38218
Share on: