CVE-2007-6581 Information

Description

Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang parameter to (1) header_album.php (2) header_blog.php or (3) header_group.php; or (4) admin_header_album.php (5) admin_header_blog.php or (6) admin_header_group.php in admin/.

Reference

http://osvdb.org/40370 http://osvdb.org/40371 http://osvdb.org/40372 http://osvdb.org/40373 http://osvdb.org/40374 http://osvdb.org/40375 http://www.inj3ct-it.org/exploit/socialengine2.txt http://www.securityfocus.com/bid/26990 https://www.exploit-db.com/exploits/4767

Share on: