CVE-2007-6471

phpay 2.02.01 - Path Traversal via Config Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-6471. PoCs published by Michael Brooks.

AI-analyzed exploit summary This exploit demonstrates a local file inclusion vulnerability in phPay due to improper input sanitization, allowing unauthorized file access and script execution on Windows systems. The PoC includes URLs that bypass protection mechanisms, especially when 'magic_quotes_gpc' is enabled.

Description

Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a ..\ (dot dot backslash) in the config parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michael Brooks · textwebappsphp
https://www.exploit-db.com/exploits/30887

This exploit demonstrates a local file inclusion vulnerability in phPay due to improper input sanitization, allowing unauthorized file access and script execution on Windows systems. The PoC includes URLs that bypass protection mechanisms, especially when 'magic_quotes_gpc' is enabled.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: phPay v2.02a
No auth needed
Prerequisites: Target running phPay v2.02a on a Windows system · PHP 'magic_quotes_gpc' directive may be enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/4231
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/485149/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26881
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39063
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28111
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3466

Scores

EPSS 0.0230
EPSS Percentile 81.0%

Details

CWE
CWE-22
Status published
Products (2)
phpay/phpay 2.2.1
phpay/phpay 2.02.01
Published Dec 20, 2007
Tracked Since Feb 18, 2026