Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.
References
Configurations
Information
Published : 2007-09-11 12:17
Updated : 2017-09-28 18:29
NVD link : CVE-2007-4820
Mitre link : CVE-2007-4820
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
sisfo_kampus
- sisfo_kampus