Vulnerabilities > CVE-2007-4092 - Unspecified vulnerability in Ifoto
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN ifoto
exploit available
Summary
Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary directories, and possibly download arbitrary photos, via a .. (dot dot) in the dir parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | iFoto 1.0 Index.PHP Directory Traversal Vulnerability. CVE-2007-4092 . Webapps exploit for php platform |
id | EDB-ID:30389 |
last seen | 2016-02-03 |
modified | 2007-07-25 |
published | 2007-07-25 |
reporter | Lostmon |
source | https://www.exploit-db.com/download/30389/ |
title | iFoto 1.0 Index.PHP Directory Traversal Vulnerability |
References
- http://lostmon.blogspot.com/2007/07/ifoto-traversal-folder-enumeration.html
- http://lostmon.blogspot.com/2007/07/ifoto-traversal-folder-enumeration.html
- http://secunia.com/advisories/26186
- http://secunia.com/advisories/26186
- http://www.securityfocus.com/archive/1/497027/100/0/threaded
- http://www.securityfocus.com/archive/1/497027/100/0/threaded
- http://www.securityfocus.com/archive/1/497113/100/0/threaded
- http://www.securityfocus.com/archive/1/497113/100/0/threaded
- http://www.securityfocus.com/bid/25065
- http://www.securityfocus.com/bid/25065