Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-1790
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-1790

Description:
Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a URL in the install_root parameter to (1) support.inc.php, (2) function.inc.php, (3) rdal_object.inc.php, (4) rdal_editor.inc.php. (5) login.inc.php, (6) request.inc.php, and (7) categories.inc.php in include/core/; (8) save.inc.php, (9) preview.inc.php, (10) edit_item.inc.php, (11) new_item.inc.php, and (12) item_info.inc.php in include/display/item/; (13) search.inc.php, (14) item_edit.inc.php, (15) register_succsess.inc.php, (16) context_menu.inc.php, (17) item_repost.inc.php, (18) balance.inc.php, (19) featured.inc.php, (20) user.inc.php, (21) buynow.inc.php, (22) install_complete.inc.php, (23) fees_info.inc.php, (24) user_feedback.inc.php, (25) admin_balance.inc.php, (26) activate.inc.php, (27) user_info.inc.php, (28) member.inc.php, (29) add_bid.inc.php, (30) items_filter.inc.php, (31) my_info.inc.php, (32) register.inc.php, (33) leave_feedback.inc.php, and (34) user_auctions.inc.php in include/display/; and (35) design/form.inc.php, (36) processor.inc.php, (37) interfaces.inc.php (38) left_menu.inc.php, (39) login.inc.php, and (40) categories.inc.php in include/.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/33335

SAID
  Secunia Advisory: SA24696

OSVDB
  34557
  34558
  34559
  34561
  34571
  34572
  34573
  34574
  34575
  34576
  34579
  34580
  34581
  34582
  34545
  34546
  34547
  34548
  34549
  34550
  34551
  34552
  34553
  34554
  34555
  34556
  34560
  34562
  34563
  34564
  34565
  34566
  34567
  34568
  34569
  34570
  34577
  34578
  34583
  34584

MILW0RM
  http://www.milw0rm.com/exploits/3607

BID
  23211


Return to the previous page.