10
CVSSv2

CVE-2007-1372

Published: 10/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote malicious users to execute arbitrary PHP code via a URL in the tpl_pgb_moddir parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

postguestbook postguestbook 0.6.1

Exploits

# PostGuestbook 061(tpl_pgb_moddir)Remote File Include Expliot # DScript: sourceforgenet/projects/postguestbook/ # Dork: "Powered by: PostGuestbook 061" # Discovered by GloD_M = [Mahmood_ali] # Homepage: wwwTryagcc # Greetz To Tryag-Team & 4lKaSrGoLd3n-Team & AsbMay's Group # VCode # include "$tpl_pgb_moddir/styles/$t ...