37515vdb entry
http://osvdb.org/37515 CVE-2007-4325
Mapos-Scripts.de Gastebuch 1.5 - 'index.php' Remote File Inclusion
Record summary
CVE-2007-4325 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMapos-Scripts.de Gastebuch 1.5 - 'index.php' Remote File InclusionExploitDB exploitby RizgarNot analyzed1 file
References
726401Third-party advisory
http://secunia.com/advisories/26401 2994Third-party advisory
http://securityreason.com/securityalert/2994 20070809 Gästebuch Version 1.5 Remote Command Execution Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/475950/100/0/threaded 25252vdb entry
http://www.securityfocus.com/bid/25252 ADV-2007-2837vdb entry
http://www.vupen.com/english/advisories/2007/2837 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4325