Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) roomNo and possibly the (2) bookid parameter.
References
Configurations
History
No history.
Information
Published : 2007-12-04 15:46
Updated : 2017-09-29 01:29
NVD link : CVE-2007-6215
Mitre link : CVE-2007-6215
CVE.ORG link : CVE-2007-6215
JSON object : View
Products Affected
web-meetme
- web-meetme
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
NVD-CWE-noinfo