Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-02-07T11:00:00

Updated: 2024-08-07T12:34:20.829Z

Reserved: 2007-02-07T00:00:00

Link: CVE-2007-0804

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-02-07T11:28:00.000

Modified: 2024-11-21T00:26:47.213

Link: CVE-2007-0804

cve-icon Redhat

No data.