Secunia Logo
 
CVE Reference: CVE-2007-1415
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-1415

Description:
Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit.php.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/32890

OSVDB
  35101
  35102
  35103
  35104
  35105
  35106
  35107
  35108
  35109
  35110
  35111
  35112
  35113
  35114
  35115
  35116
  35117
  35118
  35119
  35120
  35121
  35122
  35123
  35124
  35125

MISC
  http://advisories.echo.or.id/adv/adv68-K-159-2007.txt

MILW0RM
  http://www.milw0rm.com/exploits/3443

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/462452/100/0/threaded

BID
  22895


Return to the previous page.