** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE disputes this vulnerability because the unmodified scripts set the applicable variable to the empty string; reasonable modified copies would use a fixed pathname string.
References
Configurations
History
17 Jan 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
21 Nov 2024, 00:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://securityreason.com/securityalert/2659 - | |
References | () http://www.securityfocus.com/archive/1/466953/100/0/threaded - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/33917 - |
Information
Published : 2007-05-02 00:19
Updated : 2025-01-17 15:15
NVD link : CVE-2007-2422
Mitre link : CVE-2007-2422
CVE.ORG link : CVE-2007-2422
JSON object : View
Products Affected
comdev
- modules_builder
CWE