Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action.
References
Configurations
History
21 Nov 2024, 00:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/24955 - | |
References | () http://www.securityfocus.com/bid/23573 - | |
References | () http://www.vupen.com/english/advisories/2007/1447 - | |
References | () http://www.x-pose.org/aimstats.php - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/33742 - | |
References | () https://www.exploit-db.com/exploits/3762 - |
Information
Published : 2007-04-22 19:19
Updated : 2024-11-21 00:30
NVD link : CVE-2007-2167
Mitre link : CVE-2007-2167
CVE.ORG link : CVE-2007-2167
JSON object : View
Products Affected
aimstats
- aimstats
CWE