CVE Database
/

CVE-2007-5642

Back to search

CVE-2007-5642

Published: Oct 23, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the def_lang parameter to modules/files/list.php; the m_path parameter to (2) modules/projects/summary.inc.php or (3) modules/tasks/summary.inc.php; (4) the module parameter to modules/projects/list.php; or the module parameter to index.php in the (5) certinfo, (6) emails, (7) events, (8) fax, (9) files, (10) groupadm, (11) history, (12) info, (13) log, (14) mail, (15) messages, (16) organizations, (17) phones, (18) presence, (19) projects, (20) reports, (21) search, (22) snf, (23) syslog, (24) tasks, or (25) useradm subdirectory of modules/.

VendorProductVersions

n/a

n/a

affected
n/a

References

4549
exploit
x_refsource_EXPLOIT-DB
41951
vdb-entry
x_refsource_OSVDB
41954
vdb-entry
x_refsource_OSVDB
41975
vdb-entry
x_refsource_OSVDB
41972
vdb-entry
x_refsource_OSVDB
41955
vdb-entry
x_refsource_OSVDB
41970
vdb-entry
x_refsource_OSVDB
41960
vdb-entry
x_refsource_OSVDB
41956
vdb-entry
x_refsource_OSVDB
41974
vdb-entry
x_refsource_OSVDB
41963
vdb-entry
x_refsource_OSVDB
26148
vdb-entry
x_refsource_BID
27347
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now