Vulnerabilities > CVE-2007-2643 - Local File Include vulnerability in Pinkcrow Designs Gallery Magazin 2.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
pinkcrow-designs
exploit available

Summary

Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.

Vulnerable Configurations

Part Description Count
Application
Pinkcrow_Designs
1

Exploit-Db

descriptionmaGAZIn 2.0 (phpThumb.php src) Remote File Disclosure Vulnerability. CVE-2007-2643. Webapps exploit for php platform
fileexploits/php/webapps/3901.txt
idEDB-ID:3901
last seen2016-01-31
modified2007-05-11
platformphp
port
published2007-05-11
reporterDj7xpl
sourcehttps://www.exploit-db.com/download/3901/
titlemaGAZIn 2.0 phpThumb.php src Remote File Disclosure Vulnerability
typewebapps