Record summary

CVE-2007-4329 has a selected CVSS score of 6.8; EIP currently links 3 catalogued exploits.

Description

Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) news.php, or (3) feed.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBWeb News 1.1 - 'index.php?config[root_ordner]' Remote File InclusionExploitDB exploitby RizgarNot analyzed1 file
ExploitDB

PoC details
ExploitDBWeb News 1.1 - 'feed.php?config[root_ordner]' Remote File InclusionExploitDB exploitby RizgarNot analyzed1 file
ExploitDB

PoC details
ExploitDBWeb News 1.1 - 'news.php?config[root_ordner]' Remote File InclusionExploitDB exploitby RizgarNot analyzed1 file
ExploitDB

PoC details

References

10