Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.
References
Configurations
History
No history.
Information
Published : 2007-09-11 19:17
Updated : 2024-02-04 17:13
NVD link : CVE-2007-4820
Mitre link : CVE-2007-4820
CVE.ORG link : CVE-2007-4820
JSON object : View
Products Affected
sisfo_kampus
- sisfo_kampus
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')