Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-2199

Опубликовано: 24 апр. 2007
Источник: nvd
CVSS2: 6.8
EPSS Высокий

Описание

PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cjg_explorer_pro:cjg_explorer_pro:3.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:beta:*:*:*:*:*:*
cpe:2.3:a:nx:n_x_wcms:4.5:*:*:*:*:*:*:*
cpe:2.3:a:phpsitebackup:phpsitebackup:0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.85705
Высокий

6.8 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
почти 4 года назад

PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.

EPSS

Процентиль: 99%
0.85705
Высокий

6.8 Medium

CVSS2

Дефекты

CWE-94