CVE-2007-0050

** DISPUTED ** PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter. NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openpinboard:openpinboard:2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:24

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2007-01/0176.html - () http://archives.neohapsis.com/archives/bugtraq/2007-01/0176.html -
References () http://osvdb.org/33375 - () http://osvdb.org/33375 -
References () http://www.securityfocus.com/archive/1/455795/100/0/threaded - () http://www.securityfocus.com/archive/1/455795/100/0/threaded -
References () http://www.securityfocus.com/archive/1/455818/100/0/threaded - Exploit, Vendor Advisory () http://www.securityfocus.com/archive/1/455818/100/0/threaded - Exploit, Vendor Advisory

Information

Published : 2007-01-04 11:28

Updated : 2025-04-09 00:30


NVD link : CVE-2007-0050

Mitre link : CVE-2007-0050

CVE.ORG link : CVE-2007-0050


JSON object : View

Products Affected

openpinboard

  • openpinboard