Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-02-27T18:00:00

Updated: 2024-08-07T12:43:22.495Z

Reserved: 2007-02-27T00:00:00

Link: CVE-2007-1138

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-03-02T21:18:00.000

Modified: 2018-10-16T16:36:53.813

Link: CVE-2007-1138

cve-icon Redhat

No data.