peter bassill · operator
$ cve CVE-2007-4820 JSON

CVE-2007-4820 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.33% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2007-09-11
Last modified2026-06-16

Affected (1)

VendorProduct
sisfo kampussisfo kampus

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD