Vulnerabilities > CVE-2007-3082 - Local File Include vulnerability in SendCard

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
sendcard
exploit available

Summary

Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sc_language parameter.

Exploit-Db

descriptionSendcard <= 3.4.1 (Local File Inclusion) Remote Code Execution Exploit. CVE-2007-3082. Webapps exploit for php platform
fileexploits/php/webapps/4029.php
idEDB-ID:4029
last seen2016-01-31
modified2007-06-04
platformphp
port
published2007-06-04
reporterSilentz
sourcehttps://www.exploit-db.com/download/4029/
titleSendcard <= 3.4.1 Local File Inclusion Remote Code Execution Exploit
typewebapps