CVE-2007-4820 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.33% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-09-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sisfo kampus | sisfo kampus |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sisfo Kampus 2006 - 'blanko.preview.php' Local File Disclosure | 2007-09-08 |
References
- http://osvdb.org/39017
- http://www.securityfocus.com/bid/25605
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36533
- https://www.exploit-db.com/exploits/4380
- http://osvdb.org/39017
- http://www.securityfocus.com/bid/25605
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36533
- https://www.exploit-db.com/exploits/4380
→ the Explorer · watch your stack · NVD