20000906 PhotoAlbum 0.9.9 explorer.php Vulnerabilitymailing list
http://archives.neohapsis.com/archives/bugtraq/2000-09/0015.html CVE-2000-0872
nathan purciful phpphotoalbum 0.9.9 - Directory Traversal
Record summary
CVE-2000-0872 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBnathan purciful phpphotoalbum 0.9.9 - Directory TraversalExploitDB exploitby pestilenceNot analyzed1 file
References
41650vdb entry
http://www.securityfocus.com/bid/1650 phpphoto-dir-traverse(5198)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5198 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0872