Vulnerabilities > CVE-2007-2681 - File-Upload vulnerability in B2Evolution 1.6

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
b2evolution

Summary

Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the core_subdir parameter.

Vulnerable Configurations

Part Description Count
Application
B2Evolution
1