Vulnerabilities > CVE-2007-2642 - Local File Include vulnerability in R2K Gallery 1.7

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
r2k
exploit available

Summary

Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang2 parameter.

Vulnerable Configurations

Part Description Count
Application
R2K
1

Exploit-Db

descriptionR2K Gallery 1.7 (galeria.php lang2) Local File Inclusion Vulnerability. CVE-2007-2642. Webapps exploit for php platform
fileexploits/php/webapps/3902.txt
idEDB-ID:3902
last seen2016-01-31
modified2007-05-11
platformphp
port
published2007-05-11
reporterDj7xpl
sourcehttps://www.exploit-db.com/download/3902/
titleR2K Gallery 1.7 galeria.php lang2 Local File Inclusion Vulnerability
typewebapps