CVE-2007-0205
Alexphpteam Alex Guestbook - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.
Exploits (1)
References (8)
Scores
EPSS
0.1151
EPSS Percentile
93.7%
Details
CWE
CWE-22
Status
published
Products (4)
alexphpteam/alex_guestbook
3.12
alexphpteam/alex_guestbook
3.13
alexphpteam/alex_guestbook
4.0.1
alexphpteam/alex_guestbook
4.0.2
Published
Jan 11, 2007
Tracked Since
Feb 18, 2026