Description
Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang parameter to (1) header_album.php, (2) header_blog.php, or (3) header_group.php; or (4) admin_header_album.php, (5) admin_header_blog.php, or (6) admin_header_group.php in admin/.
Exploits (1)
References (9)
Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/40371
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/4767
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/40373
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/40370
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/40374
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/40375
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/40372
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/26990
Exploit x_refsource_misc
http://www.inj3ct-it.org/exploit/socialengine2.txt
Scores
EPSS
0.1062
EPSS Percentile
93.3%
Details
CWE
CWE-22
Status
published
Products (1)
social_engine/social_engine
2.0
Published
Dec 28, 2007
Tracked Since
Feb 18, 2026