Информационная безопасность
[RU] switch to
English Version



CVECVE-2007-1976
СтатусCandidate
Описание** DISPUTED **  PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. NOTE: the issue has been disputed by a reliable third party, stating that the application's checkSuperglobals function defends against the attack.
ВажностьHigh
CVSS score7
CVSS vector(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
PhaseAssigned (11.04.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1976
ReferencesFRSIRT : ADV-2007-1206
 MILW0RM : 3642
 VIM : 20070403 Bogus - [Xoops Module Virii Info <= 1.10 (index.php) Remote File Include Exploit]
 VIM : 20070403 Bogus - [Xoops Module Virii Info <= 1.10 (index.php) Remote File Include Exploit]
 XF : xoops-virii-index-file-include(33368)
SecurityVulns:Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server