PT-2007-6393 · Verlihub · Verlihub Control Panel
Methodman
·
Published
2007-10-09
·
Updated
2017-10-19
·
CVE-2007-5321
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Verlihub Control Panel (VHCP) versions 1.7 and earlier
Description:
A directory traversal issue exists, allowing remote attackers to include arbitrary files by utilizing a .. (dot dot) in the
page parameter of the index.php file.Recommendations:
For Verlihub Control Panel (VHCP) versions 1.7 and earlier, consider restricting access to the index.php file until a patch is available, and avoid using the
page parameter with untrusted input.Exploit
Fix
Code Injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Verlihub Control Panel