download.php in FD Script 1.3.2 and earlier allows remote attackers...
Vulnerability Description
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0620
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/23947
- http://www.securityfocus.com/archive/1/458231/100/0/threaded
- http://osvdb.org/33001
- http://securityreason.com/securityalert/2197
- http://www.vupen.com/english/advisories/2007/0383
- http://www.securityfocus.com/bid/22265
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31915
Affected Vendor
vlad leont
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.