CVE Vulnerabilities

CVE-2007-0620

Published: Jan 31, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.

Affected Software

NameVendorStart VersionEnd Version
Fd_scriptVlad_leont1.3 (including)1.3 (including)
Fd_scriptVlad_leont1.3.1 (including)1.3.1 (including)
Fd_scriptVlad_leont1.3.2 (including)1.3.2 (including)

References