Vulnerabilities > CVE-2003-1239 - Unspecified vulnerability in Wihphoto 0.86
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | WihPhoto 0.86 -dev sendphoto.php File Disclosure Vulnerability. CVE-2003-1239. Webapps exploit for php platform |
id | EDB-ID:22282 |
last seen | 2016-02-02 |
modified | 2003-02-24 |
published | 2003-02-24 |
reporter | frog |
source | https://www.exploit-db.com/download/22282/ |
title | WihPhoto 0.86 - dev sendphoto.php File Disclosure Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | WIHPHOTO_FILE_READ.NASL |
description | It is possible to make the remote host mail any file contained on its hard drive by using a flaw in WihPhoto |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11274 |
published | 2003-02-27 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11274 |
title | WihPhoto sendphoto.php Traversal Arbitrary File Access |
code |
|
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0092.html
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0092.html
- http://www.iss.net/security_center/static/11429.php
- http://www.iss.net/security_center/static/11429.php
- http://www.securityfocus.com/archive/1/312966
- http://www.securityfocus.com/archive/1/312966
- http://www.securityfocus.com/bid/6929
- http://www.securityfocus.com/bid/6929