Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3325

Опубликовано: 21 июн. 2007
Источник: nvd
CVSS2: 7.5
EPSS Высокий

Описание

PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and CVE-2007-2205.

Комментарий

LAN Management System (LMS) 1.9.6 does not appear to be a valid version. Vendor website shows up to version 1.8.10. This CVE is most likely referring to the version of 1.6.9, which is listed as the previous version to 1.8.10 on the vendor website.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lms:lan_management_system:*:*:*:*:*:*:*:*
Версия до 1.6.9 (включая)

EPSS

Процентиль: 99%
0.83996
Высокий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and CVE-2007-2205.

EPSS

Процентиль: 99%
0.83996
Высокий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other