Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6400 (PolDoc Document Management System)

BugsAlert Home > CVE-2007-6400 (PolDoc Document Management System)
 
 

Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in the filename parameter.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6400

Learn more about CVE-2007-6400 (PolDoc Document Management System)
 
Tags: cve-2007-6400 poldoc document management system

Related Items

      FrSIRT - IBM Tivoli Storage Manager Client Buffer Overflow Vulnerability

      CVE-2008-5384 (aix)

      Trojan-Downloader.Win32.Agent.qlh

      Mandriva Security Update Fixes Libexif Integer Overflow and DoS Issues

      Gentoo update for python

      MAL_NSANTI-1

      Orkut/Google Worms Compromise Over 400,000 Accounts

 

Pixel