CVE-2007-6400

Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in the filename parameter.
Configurations

Configuration 1

cpe:2.3:a:poldoc:poldoc_document_management_system:0.96:*:*:*:*:*:*:*

Information

Published : 2007-12-17 06:46

Updated : 2017-09-29 01:29


NVD link : CVE-2007-6400

Mitre link : CVE-2007-6400

Products Affected
No products.
CWE