Description
Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1 beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) forum/admin.php and (2) plotgraph/index.php in admin/modules/modules/, and (3) admin_user/mod_admuser.php and (4) ogroup/mod_group.php in admin/modules/user_account/, different vectors than CVE-2007-1446.
References (3)
Core 3
Core References
Exploit x_refsource_misc
http://www.packetstormsecurity.com/1002-exploits/oes-rfi.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56590
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/38449
Scores
EPSS
0.0239
EPSS Percentile
81.9%
Details
CWE
CWE-94
Status
published
Products (1)
danny_ho/oes
0.1 beta
Published
Jun 02, 2010
Tracked Since
Feb 18, 2026