Lucene search

K
cveMitreCVE-2007-2503
HistoryMay 04, 2007 - 1:19 a.m.

CVE-2007-2503

2007-05-0401:19:00
mitre
web.nvd.nist.gov
25
cve-2007-2503
directory traversal vulnerability
php turbulence 0.0.1 alpha
remote attackers
arbitrary local files

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.033

Percentile

91.3%

Directory traversal vulnerability in turbulence.php in PHP Turbulence 0.0.1 alpha allows remote attackers to include and execute arbitrary local files via a … (dot dot) in the GLOBALS[tcore] parameter. NOTE: this vulnerability is disputed by CVE and a reliable third party because a direct request to user/turbulence.php triggers a fatal error before inclusion

Affected configurations

Nvd
Node
php_turbulencephp_turbulenceMatch0.0.1_alpha
VendorProductVersionCPE
php_turbulencephp_turbulence0.0.1_alphacpe:2.3:a:php_turbulence:php_turbulence:0.0.1_alpha:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

High

EPSS

0.033

Percentile

91.3%

Related for CVE-2007-2503