CVE-2007-1842

Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jsboard:jsboard:*:*:*:*:*:*:*:*

History

07 Nov 2023, 02:00

Type Values Removed Values Added
References
  • {'url': 'http://kldp.net/plugins/scmcvs/cvsweb.php/jsboard-2/login.php.diff?r1=1.8;r2=1.9;cvsroot=jsboard', 'name': 'http://kldp.net/plugins/scmcvs/cvsweb.php/jsboard-2/login.php.diff?r1=1.8;r2=1.9;cvsroot=jsboard', 'tags': ['Exploit'], 'refsource': 'CONFIRM'}
  • () http://kldp.net/plugins/scmcvs/cvsweb.php/jsboard-2/login.php.diff?r1=1.8%3Br2=1.9%3Bcvsroot=jsboardĀ -

Information

Published : 2007-04-03 16:19

Updated : 2023-11-07 02:00


NVD link : CVE-2007-1842

Mitre link : CVE-2007-1842


JSON object : View

Products Affected

jsboard

  • jsboard