{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-20T22:43:43.750","vulnerabilities":[{"cve":{"id":"CVE-2007-1633","sourceIdentifier":"cve@mitre.org","published":"2007-03-23T21:19:00.000","lastModified":"2026-06-16T22:37:59.843","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php."},{"lang":"es","value":"Vulnerabilida de saldo de directorio en bbcode_ref.php en Giorgio Ciranni Splatt Forum 4.0 RC1 modulo para PHP-Nuke permite a atacantes remotos incluir y ejecutar archivos locales de su elección a través de la secuencia ..(punto punto) en el nombre del parámetro, como se demostró con la secuencia PHP dentro del fichero de log en Apache HTTP Server, el cual está incluido por bbcode_ref.php."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:giorgio_ciranni:splatt_forum:4.0_rc1:*:*:*:*:*:*:*","matchCriteriaId":"C773036F-A90A-4F79-BC53-59F7B638CDED"}]}]}],"references":[{"url":"http://osvdb.org/38599","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/23035","source":"cve@mitre.org","tags":["Exploit"]},{"url":"http://www.vupen.com/english/advisories/2007/1027","source":"cve@mitre.org"},{"url":"https://www.exploit-db.com/exploits/3518","source":"cve@mitre.org"},{"url":"http://osvdb.org/38599","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/23035","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"http://www.vupen.com/english/advisories/2007/1027","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/3518","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}