CVE-2007-4008

Entertainment Media Sharing CMS - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kw3[R]Ln · perlwebappsphp
https://www.exploit-db.com/exploits/4220

Scores

EPSS 0.0983
EPSS Percentile 93.0%

Details

CWE
CWE-22
Status published
Products (1)
entertainment_cms/entertainment_cms
Published Jul 26, 2007
Tracked Since Feb 18, 2026