7.5
CVSSv2

CVE-2007-2456

Published: 02/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote malicious users to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/.

Vulnerable Product Search on Vulmon Subscribe to Product

firefly firefly 1.1.01

Exploits

# firefly 1101 <= Remote File Include Vulnerablitiy # DScript: fresht-systems-sfrcom/unix/src/privat2/firefly-1101targz # Discovered by: Alkomandoz Hacker # Homepage: asb-maynet & mohandkocom & sniper-sacom & Tryagcom ==================================== # Exploit:[Path]/modules/admin/include/localizephp?doc_ro ...