Vulnerabilities > CVE-2006-7080 - Unspecified vulnerability in Exv2 Content Management System
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN exv2
exploit available
Summary
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | exV2. CVE-2006-7079,CVE-2006-7080. Webapps exploit for php platform |
file | exploits/php/webapps/2415.php |
id | EDB-ID:2415 |
last seen | 2016-01-31 |
modified | 2006-09-22 |
platform | php |
port | |
published | 2006-09-22 |
reporter | rgod |
source | https://www.exploit-db.com/download/2415/ |
title | exV2 <= 2.0.4.3 - extract Remote Command Execution Exploit |
type | webapps |