Описание
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIB_DIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3) stphpform.php.
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIB_DIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3) stphpform.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2007-4737
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36416
- https://www.exploit-db.com/exploits/4358
- http://osvdb.org/38929
- http://osvdb.org/38930
- http://osvdb.org/38931
- http://secunia.com/advisories/26658
- http://www.securityfocus.com/bid/25525
- http://www.vupen.com/english/advisories/2007/3092
Связанные уязвимости
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIB_DIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3) stphpform.php.