Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2007-02-07T11:00:00

Updated: 2017-10-18T14:57:01

Reserved: 2007-02-07T00:00:00


Link: CVE-2007-0804

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2007-02-07T11:28:00.000

Modified: 2017-10-19T01:30:05.020


Link: CVE-2007-0804

JSON object: View

cve-icon Redhat Information

No data.