VYPR
Unrated severityNVD Advisory· Published Jan 19, 2007· Updated Jun 16, 2026

CVE-2007-0349

CVE-2007-0349

Description

Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.

Affected products

2
  • Nicecoder/Indexu2 versions
    cpe:2.3:a:nicecoder:indexu:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nicecoder:indexu:*:*:*:*:*:*:*:*range: <=5.0
    • (no CPE)range: 5.x

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.