Vulnerabilities > CVE-2007-0173 - Local File Include vulnerability in L2J Statistik Script 0.09

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
l2j
exploit available

Summary

Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.

Vulnerable Configurations

Part Description Count
Application
L2J
1

Exploit-Db

descriptionL2J Statistik Script <= 0.09 (index.php page) Local File Include Exploit. CVE-2007-0173. Webapps exploit for php platform
fileexploits/php/webapps/3091.php
idEDB-ID:3091
last seen2016-01-31
modified2007-01-07
platformphp
port
published2007-01-07
reporterCodebreak
sourcehttps://www.exploit-db.com/download/3091/
titleL2J Statistik Script <= 0.09 index.php page Local File Include Exploit
typewebapps