Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-5642
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5642

Description:
Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the def_lang parameter to modules/files/list.php; the m_path parameter to (2) modules/projects/summary.inc.php or (3) modules/tasks/summary.inc.php; (4) the module parameter to modules/projects/list.php; or the module parameter to index.php in the (5) certinfo, (6) emails, (7) events, (8) fax, (9) files, (10) groupadm, (11) history, (12) info, (13) log, (14) mail, (15) messages, (16) organizations, (17) phones, (18) presence, (19) projects, (20) reports, (21) search, (22) snf, (23) syslog, (24) tasks, or (25) useradm subdirectory of modules/.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/37348

SAID
  Secunia Advisory: SA27347

OSVDB
  41951
  41954
  41955
  41956
  41960
  41963
  41970
  41972
  41974
  41975

MILW0RM
  http://www.milw0rm.com/exploits/4549

BID
  26148


Return to the previous page.