CVE-2007-0637

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/01/2007
Last modified:
09/04/2025

Description

Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:galeria_zdjec:galeria_zdjec:*:*:*:*:*:*:*:* 3.0 (including)