CVE-2007-2199
CJG EXPLORER PRO 3.2 - 'g_pcltar_lib_dir' Remote File Inclusion
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.
Una vulnerabilidad de inclusión remota de archivos PHP en lib/pcltar.lib.php (también se conoce como pcltar.php) en el módulo PclTar versiones 1.3 y 1.3.1 para la Biblioteca PhpConcept de Vincent Blavet, tal como se utiliza en varios productos, incluido (1) Joomla! versión 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) versión 4.5, (3) CJG EXPLORER PRO versión 3.3, y (4) phpSiteBackup versión 0.1, permite a atacantes remotos ejecutar código PHP arbitrario por medio de una URL en el parámetro g_pcltar_lib_dir .
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-04-24 CVE Reserved
- 2007-04-24 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-11-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://osvdb.org/34803 | Vdb Entry | |
http://osvdb.org/36009 | Vdb Entry | |
http://www.attrition.org/pipermail/vim/2007-May/001618.html | Mailing List | |
http://www.securityfocus.com/archive/1/466687/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/478503/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/23613 | Vdb Entry | |
http://www.securityfocus.com/bid/23708 | Vdb Entry | |
http://www.securityfocus.com/bid/24660 | Vdb Entry | |
http://www.securityfocus.com/bid/25528 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33837 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34273 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35092 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/3915 | 2024-08-07 | |
https://www.exploit-db.com/exploits/3781 | 2024-08-07 | |
https://www.exploit-db.com/exploits/4111 | 2024-08-07 | |
http://www.hackers.ir/advisories/joomla.html | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/25230 | 2018-10-16 | |
http://www.vupen.com/english/advisories/2007/1511 | 2018-10-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cjg Explorer Pro Search vendor "Cjg Explorer Pro" | Cjg Explorer Pro Search vendor "Cjg Explorer Pro" for product "Cjg Explorer Pro" | 3.3 Search vendor "Cjg Explorer Pro" for product "Cjg Explorer Pro" and version "3.3" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla Search vendor "Joomla" for product "Joomla" | 1.5.0 Search vendor "Joomla" for product "Joomla" and version "1.5.0" | beta |
Affected
| ||||||
Nx Search vendor "Nx" | N X Wcms Search vendor "Nx" for product "N X Wcms" | 4.5 Search vendor "Nx" for product "N X Wcms" and version "4.5" | - |
Affected
| ||||||
Phpsitebackup Search vendor "Phpsitebackup" | Phpsitebackup Search vendor "Phpsitebackup" for product "Phpsitebackup" | 0.1 Search vendor "Phpsitebackup" for product "Phpsitebackup" and version "0.1" | - |
Affected
|