Vulnerabilities > CVE-2007-3714 - Local File Include vulnerability in ADA Imgsvr 0.6.5

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ada
exploit available

Summary

Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this is probably a different issue than CVE-2004-2464. NOTE: it was later reported that 0.6.21 and earlier is also affected.

Vulnerable Configurations

Part Description Count
Application
Ada
1

Exploit-Db

descriptionImgSvr 0.6 Template Parameter Local File Include Vulnerability. CVE-2007-3714. Remote exploit for linux platform
idEDB-ID:30286
last seen2016-02-03
modified2007-07-10
published2007-07-10
reporterTim Brown
sourcehttps://www.exploit-db.com/download/30286/
titleImgSvr 0.6 Template Parameter Local File Include Vulnerability