6.8
CVSSv2

CVE-2007-3228

Published: 14/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CMS 4.2.12 and previous versions might allow remote malicious users to execute arbitrary PHP code via a URL in the FORUM[LIB] parameter. NOTE: by default, access to the PhpDocumentor directory tree is blocked by .htaccess.

Vulnerable Product Search on Vulmon Subscribe to Product

simian systems inc sitellite cms 4.2.12

Exploits

*sitellite*<wwwsitelliteforgecom/index/siteforge-download-action/projsitellite?dl=sitellite-4212-stabletargz> v 4212 DORK : "powered by Sitellite" FOUND BY : o0xxdark0o o0xxdark0o[at]msncom Website: wwwsitelliteorg/ DOWNLOAD : wwwsitelliteforgecom/index/siteforge-app/projsitellite REMOTE FILE ICL ...