CVE-2007-6550
PMOS Help Desk 2.4 - Remote Command Execution
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.
form.php de PMOS Help Desk 2.4 y versiones anteriores envía un re-dirección a el navegador web pero no finaliza, lo cual permite a atacantes remotos conducir ataques de inyección de evaluación directa de código dinámico y ejecutar código PHP de su elección mediante el parámetro de opciones de array.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-12-27 CVE Reserved
- 2007-12-28 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-09-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/42662 | Vdb Entry | |
http://secunia.com/advisories/28201 | Third Party Advisory | |
http://www.securityfocus.com/bid/27032 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/4321 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39274 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/4789 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pmos Helpdesk Search vendor "Pmos Helpdesk" | Pmos Helpdesk Search vendor "Pmos Helpdesk" for product "Pmos Helpdesk" | <= 2.4 Search vendor "Pmos Helpdesk" for product "Pmos Helpdesk" and version " <= 2.4" | - |
Affected
|