CVE-2007-3217

Prototype of an PHP application 0.1 - RCE

Title source: llm
STIX 2.1

Description

Multiple PHP remote file inclusion vulnerabilities in Prototype of an PHP application 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the path_inc parameter to (1) index.php in gestion/; (2) identification.php, (3) disconnect.php, (4) loginliste.php, (5) loginmodif.php, (6) index.php, and (7) ident.inc.php in ident/; (8) menuadministration.php and (9) menuprincipal.php in menu/; (10) param.inc.php in param/; (11) index.php in plugins/phpgacl/; and (12) index.php and (13) common.inc.php.

Exploits (12)

exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30126
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30128
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30129
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30127
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30125
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30122
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30121
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30123
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30119
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30124
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30120
exploitdb WRITEUP VERIFIED
by pito pito · textwebappsphp
https://www.exploit-db.com/exploits/30118

References (17)

Core 17
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37158
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2812
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37155
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37161
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/470245/100/100/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24266
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34679
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37160
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37153
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37151
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37159
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37156
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37157
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37152
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37150
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37154
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37149

Scores

EPSS 0.0868
EPSS Percentile 92.5%

Details

Status published
Products (1)
prototype_of_an_php_application/prototype_of_an_php_application 0.1
Published Jun 14, 2007
Tracked Since Feb 18, 2026