Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-2003

Опубликовано: 12 апр. 2007
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:inoutmailinglistmanager:inoutmailinglistmanager:*:*:*:*:*:*:*:*
Версия до 3.1 (включая)

EPSS

Процентиль: 91%
0.06244
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect.

EPSS

Процентиль: 91%
0.06244
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other