VYPR
Unrated severityNVD Advisory· Published Dec 20, 2007· Updated Apr 23, 2026

CVE-2007-6471

CVE-2007-6471

Description

Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory traversal attacks and include and execute arbitrary local files via a ..\ (dot dot backslash) in the config parameter.

Affected products

2
  • Phpay/Phpay2 versions
    cpe:2.3:a:phpay:phpay:2.2.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:phpay:phpay:2.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:phpay:phpay:2.02.01:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.