CVE Database
/

CVE-2007-5253

Back to search

CVE-2007-5253

Published: Oct 6, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00) sequence followed by an image file extension, as demonstrated by a request for a ".txt%00.gif" file. NOTE: this might be a directory traversal vulnerability.

VendorProductVersions

n/a

n/a

affected
n/a

References

38580
vdb-entry
x_refsource_OSVDB
27061
third-party-advisory
x_refsource_SECUNIA
25928
vdb-entry
x_refsource_BID
30639
exploit
x_refsource_EXPLOIT-DB
3194
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now