CVE-2007-3707

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/07/2007
Last modified:
09/04/2025

Description

Directory traversal vulnerability in index.php in CodeIgniter 1.5.3 before 20070628, when enable_query_strings is true, allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:codeigniter:codeigniter:1.5.3:*:*:*:*:*:*:*