CVE-2007-0704

PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter, a different vector than CVE-2006-4669. NOTE: the documentation says to remove install.php after installation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:somery:somery:0.4.6:*:*:*:*:*:*:*

History

21 Nov 2024, 00:26

Type Values Removed Values Added
References () http://osvdb.org/33608 - () http://osvdb.org/33608 -
References () http://www.attrition.org/pipermail/vim/2007-February/001265.html - Exploit () http://www.attrition.org/pipermail/vim/2007-February/001265.html - Exploit
References () https://www.exploit-db.com/exploits/2329 - () https://www.exploit-db.com/exploits/2329 -

Information

Published : 2007-02-04 00:28

Updated : 2024-11-21 00:26


NVD link : CVE-2007-0704

Mitre link : CVE-2007-0704

CVE.ORG link : CVE-2007-0704


JSON object : View

Products Affected

somery

  • somery