Description
Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by laurent gaffie · textwebappsphp
https://www.exploit-db.com/exploits/29634
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/460913/100/0/threaded
Exploit third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/2332
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/22669
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/33138
Scores
EPSS
0.0425
EPSS Percentile
88.8%
Details
CWE
CWE-22
Status
published
Products (1)
cromosoft/simple_plantilla_php
Published
Mar 02, 2007
Tracked Since
Feb 18, 2026