Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitrary files or list arbitrary directories, and obtain the installation path, via a .. (dot dot) in the d_private parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."
References
Configurations
History
21 Nov 2024, 00:29
Type | Values Removed | Values Added |
---|---|---|
References | () http://securityreason.com/securityalert/2522 - | |
References | () http://www.securityfocus.com/archive/1/464272/100/0/threaded - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/33333 - |
Information
Published : 2007-04-03 16:19
Updated : 2024-11-21 00:29
NVD link : CVE-2007-1850
Mitre link : CVE-2007-1850
CVE.ORG link : CVE-2007-1850
JSON object : View
Products Affected
drake_team
- drake_cms
CWE