CVE-2007-0804
Published Feb 7, 2007
Last updated 7 years ago
Overview
- Description
- Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ggcms:ggcms:1.1.0_rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31E5135C-B0B2-4143-B408-A8C4B90D0B46" } ], "operator": "OR" } ] } ]