nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-5600 CVE-2007-5600
Artmedic CMS 3.4 - 'index.php' Local File Inclusion
Record summary
CVE-2007-5600 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Incomplete blacklist vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftps, (3) ssh2.sftp, or (4) ssh2.scp URL, in the page parameter, for which PHP remote file inclusion is blocked only for http, https, and ftp URLs.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBArtmedic CMS 3.4 - 'index.php' Local File InclusionExploitDB exploitby iNsNot analyzed1 file
References
24538exploit
https://www.exploit-db.com/exploits/4538