7.5
CVSSv2

CVE-2007-3370

Published: 22/06/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote malicious users to execute arbitrary PHP code via a URL in (1) the sunPath parameter to include.php or (2) the dir parameter to skin/board/default/doctype.php.

Vulnerable Product Search on Vulmon Subscribe to Product

kim kyoung min sun board 1.00.00_alpha

Exploits

# Sun Board 10000 Alpha Multiple Remote File Inclusion Vulnerabilities # DScript : meshdlsourceforgenet/sourceforge/sunboard/sunboardzip # VCode : require $sunPath'configphp'; require_once $sunPath'dbms/'$dbtype'php'; # In : /includephp # Exploits : /includephp?sunPath=Shelltxt? # VCode 2 : ...