** DISPUTED ** PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter. NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete.
References
Configurations
History
21 Nov 2024, 00:24
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2007-01/0176.html - | |
References | () http://osvdb.org/33375 - | |
References | () http://www.securityfocus.com/archive/1/455795/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/455818/100/0/threaded - Exploit, Vendor Advisory |
Information
Published : 2007-01-04 11:28
Updated : 2025-04-09 00:30
NVD link : CVE-2007-0050
Mitre link : CVE-2007-0050
CVE.ORG link : CVE-2007-0050
JSON object : View
Products Affected
openpinboard
- openpinboard
CWE