Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6567 (XZero Community Classifieds)

BugsAlert Home > CVE-2007-6567 (XZero Community Classifieds)
 
 

Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter in a page view action.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6567

Learn more about CVE-2007-6567 (XZero Community Classifieds)
 
Tags: cve-2007-6567 xzero community classifieds

Related Items

      CVE-2008-2713 (ClamAV)

      eXPert PDF EditorX ActiveX Control "extractPagesToFile()" Insecure Method

      Mandriva: Subject: [Security Announce] [ MDVSA-2008:244 ] mozilla-firefox

      FrSIRT - BFup ActiveX Control "FilePath" Property Buffer Overflow Vulnerability

      Music Unleashes the Malware Beast

      CVE-2008-4371 (availscript_article_script)

      TROJ_SMALL.JIU

 

Pixel