Record summary

CVE-2007-4327 has a selected CVSS score of 6.8; EIP currently links 2 catalogued exploits.

Description

Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php or (2) datei.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBFile Uploader 1.1 - 'index.php?config[root_ordner]' Remote File InclusionExploitDB exploitby RizgarNot analyzed1 file
ExploitDB

PoC details
ExploitDBFile Uploader 1.1 - 'datei.php?config[root_ordner]' Remote File InclusionExploitDB exploitby RizgarNot analyzed1 file
ExploitDB

PoC details

References

9