Unrated severityNVD Advisory· Published Jan 18, 2007· Updated Apr 23, 2026
CVE-2007-0335
CVE-2007-0335
Description
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.
Affected products
1- cpe:2.3:a:jax_scripts:jax_petition_book:1.0.3.06:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- osvdb.org/32835nvd
- osvdb.org/32836nvd
- secunia.com/advisories/23784nvd
- securityreason.com/securityalert/2161nvd
- www.securityfocus.com/archive/1/456981/100/0/threadednvd
- www.securityfocus.com/archive/1/456989/100/0/threadednvd
- www.securityfocus.com/archive/1/457077/100/0/threadednvd
- www.securityfocus.com/bid/22072nvd
- www.vupen.com/english/advisories/2007/0220nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/31543nvd
News mentions
0No linked articles in our index yet.