Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2007-0098
StatusCandidate
DescriptionDirectory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.
SeverityMedium
CVSS score5,6
CVSS vector(AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N)
PhaseAssigned (05.01.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0098
ReferencesFRSIRT : ADV-2007-0035
 MILW0RM : 3075
 XF : verliadmin-language-file-include(31241)
SecurityVulns:Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server