CVE-2007-4180 describes a disputed directory traversal vulnerability in Pluck 4.3, specifically within the data/inc/theme.php file when register_globals is enabled. The alleged vulnerability would allow remote attackers to read arbitrary local files by manipulating the 'file' parameter with directory traversal sequences. While initially rated with a CVSS score of 5.0 (medium severity) indicating potential confidentiality impact, both the CVE and a reliable third party dispute its existence due to the code's fixed argument usage with fputs, which prevents file reading. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3CPE matchmatch criteria | cpe:2.3:a:pluck:pluck:4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.