Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-2084

Опубликовано: 18 апр. 2007
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the auth_method parameter to (1) index.php, (2) list.php, (3) postreview.php, (4) reindex.php, (5) sections.php, (6) templates.php, (7) userinfo.php, (8) users.php, and (9) view.php in admin/. NOTE: this issue has been disputed by a reliable third party, who states that $auth_method is defined before use

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mobilepublisherphp:mobilepublisherphp:1.1.2:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01197
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
почти 4 года назад

** DISPUTED ** PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the auth_method parameter to (1) index.php, (2) list.php, (3) postreview.php, (4) reindex.php, (5) sections.php, (6) templates.php, (7) userinfo.php, (8) users.php, and (9) view.php in admin/. NOTE: this issue has been disputed by a reliable third party, who states that $auth_method is defined before use.

EPSS

Процентиль: 79%
0.01197
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94