Show plain JSON{"id": "CVE-2007-2859", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false}]}, "published": "2007-05-24T19:30:00.000", "references": [{"url": "http://osvdb.org/38101", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/38102", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/38103", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/38104", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/38105", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/38106", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/38107", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/38108", "source": "cve@mitre.org"}, {"url": "http://securityreason.com/securityalert/2735", "source": "cve@mitre.org"}, {"url": "http://www.attrition.org/pipermail/vim/2007-May/001626.html", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/469219/100/0/threaded", "source": "cve@mitre.org"}, {"url": "http://www.xmors-seurity.com/advisory/SimpGB%28rfi%29.txt", "tags": ["URL Repurposed"], "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34428", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/38101", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/38102", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/38103", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/38104", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/38105", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/38106", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/38107", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/38108", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://securityreason.com/securityalert/2735", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.attrition.org/pipermail/vim/2007-May/001626.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/469219/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.xmors-seurity.com/advisory/SimpGB%28rfi%29.txt", "tags": ["URL Repurposed"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34428", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "Multiple PHP remote file inclusion vulnerabilities in SimpGB 1.46.0 allow remote attackers to execute arbitrary PHP code via a URL in the path_simpgb parameter to (1) guestbook.php, (2) search.php, (3) mailer.php, (4) avatars.php, (5) ccode.php, (6) comments.php, (7) emoticons.php, (8) gbdownload.php, and possibly other PHP scripts."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de inclusi\u00f3n remota de archivo en PHP en el SimpGB 1.46.0 permiten a atacantes remotos ejecutar c\u00f3digo PHP de su elecci\u00f3n mediante una URL en el par\u00e1metro (1) guestbook.php, (2) search.php, (3) mailer.php, (4) avatars.php, (5) ccode.php, (6) comments.php, (7) emoticons.php, (8) gbdownload.php y, posiblemente, otras secuencias de comandos PHP."}], "lastModified": "2025-04-09T00:30:58.490", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:simpgb:simpgb:1.46.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "070EC1DF-8EB7-444C-B112-33EBE65BB08E"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}