Vulnerability Details CVE-2007-0205
Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.101
EPSS Ranking 92.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2007-0205
-
cpe:2.3:a:alexphpteam:alex_guestbook:3.12
-
cpe:2.3:a:alexphpteam:alex_guestbook:3.13
-
cpe:2.3:a:alexphpteam:alex_guestbook:4.0.1
-
cpe:2.3:a:alexphpteam:alex_guestbook:4.0.2