CVE-2007-4641
Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.
- Affected products
- Apache, Pakupaku Cms
- Pakupaku Pakupaku Cms
- ≤ 0.4
- CVSS 2.0
- 6.4 MEDIUM
- EPSS
- 2.7% (85th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2007-08-31
CVE-2007-4641 at NVD
1 known exploit for CVE-2007-4641
Proof-of-concept code and exploit modules indexed by Sploitus