Vulnerabilities > CVE-2007-0329 - Directory Traversal vulnerability in Jv2 Folder Gallery

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
joonas-viljanen
exploit available

Summary

download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallerysetup.php. NOTE: this issue might be resultant from a directory traversal vulnerability.

Vulnerable Configurations

Part Description Count
Application
Joonas_Viljanen
1

Exploit-Db

descriptionJV2 Folder Gallery 3.0 (download.php) Remote File Disclosure Exploit. CVE-2007-0329. Webapps exploit for php platform
fileexploits/php/webapps/3125.c
idEDB-ID:3125
last seen2016-01-31
modified2007-01-14
platformphp
port
published2007-01-14
reporterPeTrO
sourcehttps://www.exploit-db.com/download/3125/
titleJV2 Folder Gallery 3.0 - download.php Remote File Disclosure Exploit
typewebapps