36262vdb entry
http://osvdb.org/36262 CVE-2007-3792
Dating Gold 3.0.5 - 'header.php?int_path' Remote File Inclusion
Record summary
CVE-2007-3792 has a selected CVSS score of 4.3; EIP currently links 3 catalogued exploits.
Description
Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter to (1) header.php, (2) footer.php, or (3) secure.admin.php in templates/.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBDating Gold 3.0.5 - 'header.php?int_path' Remote File InclusionExploitDB exploitby mostafa_ragabNot analyzed1 file
ExploitDBDating Gold 3.0.5 - 'footer.php?int_path' Remote File InclusionExploitDB exploitby mostafa_ragabNot analyzed1 file
ExploitDBDating Gold 3.0.5 - 'secure.admin.php?int_path' Remote File InclusionExploitDB exploitby mostafa_ragabNot analyzed1 file
References
836263vdb entry
http://osvdb.org/36263 36264vdb entry
http://osvdb.org/36264 2888Third-party advisory
http://securityreason.com/securityalert/2888 20070713 AzDG Dating Gold v3.0.5 ===> Remote File Include Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/473664/100/0/threaded 24910vdb entry
http://www.securityfocus.com/bid/24910 azdgdating-intpath-file-include(35428)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35428 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-3792