6.8
CVSSv2

CVE-2007-2166

Published: 22/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the cfgPathToProjectAdmin parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

opensurveypilot opensurveypilot

Exploits

# osp <= 121 (cfgPathToProjectAdmin) Remote File Include Vulnerablities # DScript: nlcacinternationalstudentsasnau/osp101RC1tar sourceforgenet/projects/osp/ << latest # Discovered by: Alkomandoz Hacker # Homepage: wwwasb-maynet & TrYaGCoM & MoHaNdKoCoM # Exploit: [Path]/opensurveypilot/a ...