PT-2007-5638 · Dalai · Dalai Forum

Published

2007-08-21

·

Updated

2018-10-15

·

CVE-2007-4457

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dalai Forum version 1.1
Description The issue allows remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the chemin parameter of the forumreply.php file, enabling directory traversal.
Recommendations For Dalai Forum version 1.1, consider restricting access to the chemin parameter in the forumreply.php file to prevent directory traversal attacks. As a temporary workaround, restrict the use of the forumreply.php file until a patch is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4457

Affected Products

Dalai Forum