Vulnerability record · CVE-2007-4723 · published 5 September 2007
CVE-2007-4723: Ragnarok online control panel project ragnarok online control panel path traversal vulnerability
RRagnarok Online Control Panel Project · Ragnarok Online Control Panel
Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
Description
Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://osvdb.org/45879 | Broken Link |
| http://securityreason.com/securityalert/3100 | Third Party Advisory |
| http://www.securityfocus.com/archive/1/478263/100/0/threaded | Third Party AdvisoryVDB Entry |
| http://osvdb.org/45879 | Broken Link |
| http://securityreason.com/securityalert/3100 | Third Party Advisory |
| http://www.securityfocus.com/archive/1/478263/100/0/threaded | Third Party AdvisoryVDB Entry |
Track CVE-2007-4723 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-4723), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.