Vulnerabilities > CVE-2007-2659 - Directory Traversal vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
bugada-andrea
exploit available

Summary

Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obtain script source code via a .. (dot dot) in the directory parameter in a downloadfile action.

Vulnerable Configurations

Part Description Count
Application
Bugada_Andrea
1

Exploit-Db

descriptionphpAtm 1.30 (downloadfile) Remote File Disclosure Vulnerability. CVE-2007-2659. Webapps exploit for php platform
fileexploits/php/webapps/3918.txt
idEDB-ID:3918
last seen2016-01-31
modified2007-05-13
platformphp
port
published2007-05-13
reporterAli.Mohajem
sourcehttps://www.exploit-db.com/download/3918/
titlephpAtm 1.30 downloadfile Remote File Disclosure Vulnerability
typewebapps