7.5
CVSSv2

CVE-2007-1233

Published: 03/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the stwc_counter_verzeichniss parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

stwc-counter stwc-counter 3.1.0

stwc-counter stwc-counter 3.0.3

stwc-counter stwc-counter 2.8.0

stwc-counter stwc-counter 2.7.1

stwc-counter stwc-counter 2.6.1

stwc-counter stwc-counter 2.6.0

stwc-counter stwc-counter 2.2.6

stwc-counter stwc-counter

stwc-counter stwc-counter 3.0.0

stwc-counter stwc-counter 2.9.1

stwc-counter stwc-counter 2.6.5

stwc-counter stwc-counter 2.6.4

stwc-counter stwc-counter 2.4.0

stwc-counter stwc-counter 2.3.1

stwc-counter stwc-counter 2.2.2

stwc-counter stwc-counter 2.2.1

stwc-counter stwc-counter 1.22

stwc-counter stwc-counter 1.21

stwc-counter stwc-counter 2.2.5

stwc-counter stwc-counter 2.1.0

stwc-counter stwc-counter 2.0.2

stwc-counter stwc-counter 1.11

stwc-counter stwc-counter 1.1

stwc-counter stwc-counter 1.02

stwc-counter stwc-counter 3.0.2

stwc-counter stwc-counter 3.0.1

stwc-counter stwc-counter 2.7.0

stwc-counter stwc-counter 2.6.6

stwc-counter stwc-counter 2.5.2

stwc-counter stwc-counter 2.5.1

stwc-counter stwc-counter 2.5.0

stwc-counter stwc-counter 2.2.4

stwc-counter stwc-counter 2.2.3

stwc-counter stwc-counter 2.0.1

stwc-counter stwc-counter 2.0.0

stwc-counter stwc-counter 1.01

stwc-counter stwc-counter 3.3.0

stwc-counter stwc-counter 3.2.0

stwc-counter stwc-counter 2.9.0

stwc-counter stwc-counter 2.8.1

stwc-counter stwc-counter 2.6.3

stwc-counter stwc-counter 2.6.2

stwc-counter stwc-counter 2.3.0

stwc-counter stwc-counter 2.2.7

stwc-counter stwc-counter 2.2.0

stwc-counter stwc-counter 2.1.1

stwc-counter stwc-counter 1.2

stwc-counter stwc-counter 1.12

Exploits

<?php //File Inclusion Exploit for STWC-Counter <= 3400 //Found and Exploit Coded by burncycle - burncycle[(at)]robert-beran[(dot)]de //| //Vendor: wwwstwc-counterde/ //Dork: wwwstwc-counterde //| //Bug in "downloadcounterphp": // //$stwc_verzeichniss = $stwc_counter_verzeichniss; // //include($stwc_verzeichniss "funktio ...