CVE-2007-6552

AuraCMS 2.2 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the act parameter, possibly involving the news pilih component; as demonstrated by including admin/admin_users.php to bypass a protection mechanism against direct request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by k1tk4t · perlwebappsphp
https://www.exploit-db.com/exploits/4786

Scores

EPSS 0.0101
EPSS Percentile 77.2%

Details

CWE
CWE-22
Status published
Products (1)
auracms/auracms 2.2
Published Dec 28, 2007
Tracked Since Feb 18, 2026