7.5
CVSSv2

CVE-2007-2014

Published: 12/04/2007 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote malicious users to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.

Vulnerable Product Search on Vulmon Subscribe to Product

mynews mynews 4.2.2

Exploits

source: wwwsecurityfocuscom/bid/23398/info MyNews is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process This may allow the attacker ...