Unrated severityNVD Advisory· Published Apr 10, 2007· Updated Apr 23, 2026
CVE-2007-1906
CVE-2007-1906
Description
Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter.
Affected products
2- cpe:2.3:a:ecardmax.com:hot_editor:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:mybb:mybb_hot_editor_plugin:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.expw0rm.com/hot-editor-v40-local-file-inclusion_no113.htmlnvdExploit
- www.expw0rm.com/mybb-hot-editor-plugin-local-file-inclusion_no114.htmlnvdExploit
- www.securityfocus.com/bid/23377nvdExploitVendor Advisory
- osvdb.org/34776nvd
- secunia.com/advisories/24825nvd
- securityreason.com/securityalert/2533nvd
- www.securityfocus.com/archive/1/465092/100/0/threadednvd
- www.securityfocus.com/archive/1/465094/100/0/threadednvd
- www.vupen.com/english/advisories/2007/1315nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/33521nvd
News mentions
0No linked articles in our index yet.