Vulnerabilities > CVE-2007-2507 - Directory Traversal vulnerability in Treble Designs 1024 CMS 0.7

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
treble-designs
exploit available

Summary

Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the item parameter.

Vulnerable Configurations

Part Description Count
Application
Treble_Designs
1

Exploit-Db

description1024 CMS 0.7 (download.php item) Remote File Disclosure Vulnerability. CVE-2007-2507. Webapps exploit for php platform
fileexploits/php/webapps/3832.txt
idEDB-ID:3832
last seen2016-01-31
modified2007-05-02
platformphp
port
published2007-05-02
reporterDj7xpl
sourcehttps://www.exploit-db.com/download/3832/
title1024 CMS 0.7 download.php item Remote File Disclosure Vulnerability
typewebapps