CVE-2007-0616

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/01/2007
Last modified:
21/11/2024

Description

Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories via ".." sequences in the album parameter to index.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zenphoto:zenphoto:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:zenphoto:zenphoto:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:zenphoto:zenphoto:1.0.6:*:*:*:*:*:*:*