CVE-2006-7133
php_upload_tool 1.0 - Directory Traversal via Filename Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-7133. PoCs published by Craig Heffner.
AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in PHP Upload Tool 1.0, allowing attackers to read arbitrary files via unsanitized input in the 'filename' parameter. No actual exploit code is present, only examples of vulnerable URLs.
Description
Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter.
Exploits (1)
The provided text describes a directory traversal vulnerability in PHP Upload Tool 1.0, allowing attackers to read arbitrary files via unsanitized input in the 'filename' parameter. No actual exploit code is present, only examples of vulnerable URLs.