CVE Vulnerabilities

CVE-2007-0804

Published: Feb 07, 2007 | Modified: Oct 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via .. sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.

Affected Software

Name Vendor Start Version End Version
Ggcms Ggcms 1.1.0_rc1 1.1.0_rc1

References