peter bassill · operator
$ cve CVE-2007-1138 JSON

CVE-2007-1138 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 85)

Patch early

A public exploit exists.

Description

Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.65% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2007-03-02
Last modified2026-06-16

Affected (1)

VendorProduct
cromosoftsimple plantilla php

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD