CVE Vulnerabilities

CVE-2007-0804

Published: Feb 07, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via .. sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.

Affected Software

NameVendorStart VersionEnd Version
GgcmsGgcms1.1.0_rc1 (including)1.1.0_rc1 (including)

References