CVE-2007-6376

Francisco Burzi PHP-Nuke 8.0 - Path Traversal via autohtml.php filename Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-6376. PoCs published by d3v1l.

AI-analyzed exploit summary The provided text describes a local file inclusion (LFI) vulnerability in Dance Music software, where unsanitized user input in the 'filename' parameter of 'autohtml.php' allows unauthorized file access. The example demonstrates path traversal to read '/etc/passwd'.

Description

Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filename parameter, a different vector than CVE-2006-4190. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by d3v1l · textwebappsphp
https://www.exploit-db.com/exploits/30881

The provided text describes a local file inclusion (LFI) vulnerability in Dance Music software, where unsanitized user input in the 'filename' parameter of 'autohtml.php' allows unauthorized file access. The example demonstrates path traversal to read '/etc/passwd'.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Dance Music (version unspecified)
No auth needed
Prerequisites: Network access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/39507
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26807

Scores

EPSS 0.0259
EPSS Percentile 83.3%

Details

CWE
CWE-22
Status published
Products (1)
francisco_burzi/php-nuke 8.0_final
Published Dec 15, 2007
Tracked Since Feb 18, 2026