CVE-2007-1138
Cromosoft Simple Plantilla PHP - Path Traversal and Arbitrary File Read via nfolder Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1138. PoCs published by laurent gaffie.
AI-analyzed exploit summary The provided text describes a local file-include vulnerability and an arbitrary file-upload vulnerability in Simple Plantilla PHP. It includes a sample URL demonstrating the directory-traversal attack but lacks executable exploit code.
Description
Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.
Exploits (1)
The provided text describes a local file-include vulnerability and an arbitrary file-upload vulnerability in Simple Plantilla PHP. It includes a sample URL demonstrating the directory-traversal attack but lacks executable exploit code.