CVE-2007-4181
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
PHP remote file inclusion vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: A reliable third party disputes this vulnerability because the applicable include is within a function that does not receive the dir parameter from an HTTP request
** IMPUGNADA ** Vulnerabilidad de inclusión remota de archivo en PHP en data/inc/theme.php de Pluck 4.3, cuando register_globals está habilitado, permite a atacantes remotos ejecutar código PHP de su elección mediante un URL en el parámetro dir. NOTA: Una tercera parte de confianza impugna esta vulnerabilidad ya que la inclusión aplicable está dentro de una función que no recibe el parámetro dir de una petición HTTP.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-08-07 CVE Reserved
- 2007-08-08 CVE Published
- 2024-06-11 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://outlaw.aria-security.info/?p=12 | X_refsource_misc | |
http://securityreason.com/securityalert/2973 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/475323/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35756 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.attrition.org/pipermail/vim/2007-August/001752.html | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|