CVE-2007-5813
ISPworker 1.21 - Path Traversal via TicketID or Filename Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5813. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in ISPworker 1.21, allowing remote attackers to disclose arbitrary files by manipulating the 'ticketid' or 'filename' parameter in the download.php script.
Description
Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ticketid and (2) filename parameters.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in ISPworker 1.21, allowing remote attackers to disclose arbitrary files by manipulating the 'ticketid' or 'filename' parameter in the download.php script.