CVE-2007-6471

Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a .. (dot dot backslash) in the config parameter.
Configurations

Configuration 1

cpe:2.3:a:phpay:phpay:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:phpay:phpay:2.02.01:*:*:*:*:*:*:*

Information

Published : 2007-12-20 12:46

Updated : 2018-10-15 09:54


NVD link : CVE-2007-6471

Mitre link : CVE-2007-6471

Products Affected
No products.
CWE