Vulnerabilities > CVE-2007-2303 - File-Upload vulnerability in News Manager Deluxe News Manager Deluxe 1.0.1

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
news-manager-deluxe
exploit available

Summary

Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.

Vulnerable Configurations

Part Description Count
Application
News_Manager_Deluxe
1

Exploit-Db

descriptionNMDeluxe 1.0.1 (footer.php template) Local File Inclusion Exploit. CVE-2007-2303. Webapps exploit for php platform
fileexploits/php/webapps/3742.pl
idEDB-ID:3742
last seen2016-01-31
modified2007-04-15
platformphp
port
published2007-04-15
reporterBeyazKurt
sourcehttps://www.exploit-db.com/download/3742/
titleNMDeluxe 1.0.1 footer.php template Local File Inclusion Exploit
typewebapps