7.5
CVSSv2

CVE-2007-2609

Published: 11/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote malicious users to execute arbitrary PHP code via a URL in the (a) ETCDIR parameter to (1) libs/lom.php; (2) lom_update.php, (3) check-lom.php, and (4) weigh_keywords.php in scripts/; the (b) LIBSDIR parameter to (5) logout.php, (6) help.php, (7) index.php, (8) login.php; and the ETCDIR parameter to (9) web/lom.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnuedu gnu edu 1.3b2

Exploits

# gnuedu 13b2 Multiple Remote File Inclusion Vulnerabilities # DScript: gnueduofsetorg/download/ # Discovered by: GolD_M = [Mahmood_ali] # Homepage: wwwTryagCom/cc # Exploit:[Path]/libs/lomphp?ETCDIR=Shell # Exploit:[Path]/scripts/lom_updatephp?ETCDIR=Shell # Exploit:[Path]/scripts/check-lomphp?ETCDIR=Shell # Exploit:[Path]/s ...