24983Third-party advisory
http://secunia.com/advisories/24983 CVE-2007-2202
ACVSWS - 'Transport.php' Remote File Inclusion
Record summary
CVE-2007-2202 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CheminInclude parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBACVSWS - 'Transport.php' Remote File InclusionExploitDB exploitby MoHaNdKoNot analyzed1 file
References
72609Third-party advisory
http://securityreason.com/securityalert/2609 20070423 acvsws_php5_v1.0 <= Multiple Remote File Include Vulnerablitiymailing list
http://www.securityfocus.com/archive/1/466695/100/0/threaded 23603vdb entry
http://www.securityfocus.com/bid/23603 ADV-2007-1509vdb entry
http://www.vupen.com/english/advisories/2007/1509 acvswebservices-transport-file-include(33840)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/33840 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-2202