Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-1986
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-1986

Description:
Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_path_core parameter to inc/core_profile.header.php, the (2) template_path_core parameter to template/barnraiser_01/maint_contact_view.tpl.php, and the (3) template_path parameter to template/barnraiser_01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/33427

SAID
  Secunia Advisory: SA24773

OSVDB
  34623
  34624
  34625

MILW0RM
  http://www.milw0rm.com/exploits/3659

BID
  23303


Return to the previous page.