CVE Feed

    Dashboard / CVE / CVE-2007-6397

    CVE-2007-6397

    Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a .. (dot dot) in the username parameter when registering a user account, and (2) read arbitrary PHP files via a .. (dot dot) in (a) the topic parameter in a topic action or (b) the username parameter in a viewprofile action.

    Published:Dec 17, 2007
    Last Modified:Apr 23, 2026
    EPS:Dec 17, 2007
    EPSS Score:0.06528
    CVSS Score:5

    Affected Products

    Vendor
    Flat Php
    Product
    Board

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High