CVE-2007-0205

Alexphpteam Alex Guestbook - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkFig · phpwebappsphp
https://www.exploit-db.com/exploits/3103

Scores

EPSS 0.1151
EPSS Percentile 93.7%

Details

CWE
CWE-22
Status published
Products (4)
alexphpteam/alex_guestbook 3.12
alexphpteam/alex_guestbook 3.13
alexphpteam/alex_guestbook 4.0.1
alexphpteam/alex_guestbook 4.0.2
Published Jan 11, 2007
Tracked Since Feb 18, 2026