CVE-2007-5776
i-Gallery 3.4 - Path Traversal via Encoded Backslash Sequences in d Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5776. PoCs published by hackerbinhphuoc.
AI-analyzed exploit summary The exploit describes a directory traversal vulnerability in i-Gallery 3.4, allowing remote attackers to read arbitrary local files via a crafted URL. The provided example demonstrates the issue but lacks executable code.
Description
Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to read arbitrary files via encoded backslash sequences in the d parameter, as demonstrated by a "%5c../../%5c" sequence.
Exploits (1)
The exploit describes a directory traversal vulnerability in i-Gallery 3.4, allowing remote attackers to read arbitrary local files via a crafted URL. The provided example demonstrates the issue but lacks executable code.