Vulnerabilities > CVE-2007-1930 - Information Disclosure vulnerability in Cattadoc 2.21/3.0

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
cattadoc
exploit available

Summary

Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitrary files via a .. (dot dot) in the fn1 parameter.

Vulnerable Configurations

Part Description Count
Application
Cattadoc
2

Exploit-Db

descriptioncattaDoc 2.21 (download2.php fn1) Remote File Disclosure Vulnerability. CVE-2007-1930. Webapps exploit for php platform
fileexploits/php/webapps/3677.txt
idEDB-ID:3677
last seen2016-01-31
modified2007-04-06
platformphp
port
published2007-04-06
reporterGoLd_M
sourcehttps://www.exploit-db.com/download/3677/
titlecattaDoc 2.21 download2.php fn1 Remote File Disclosure Vulnerability
typewebapps