7.5
CVSSv2

CVE-2007-2341

Published: 27/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote malicious users to execute arbitrary PHP code via a URL in the pg parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbandmanager phpbandmanager 0.8

Exploits

author:koray greetz:cigiciginet script:sourceforgenet/projects/phpbandmanager allow_url_fopen:on or register_globals:on vuln; /bandmanager/suite/indexphp include($_GET['pg']"php"); example; wwwvictimcom/suite/indexphp?pg=shell link? # milw0rmcom [2007-04-26] ...