6.8
CVSSv2

CVE-2007-5138

Published: 28/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote malicious users to execute arbitrary PHP code via a URL in the view parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

lustig lustig.cms 2.5_beta

Exploits

# lustigcms BETA 25 (forumphp view) Remote File Inclusion Vulnerabilities # DScripts : dfndlsourceforgenet/sourceforge/lustig-cms/lustigcms_beta_25_2zip # VCode : Line 12 13 14 # if(isset($view)) # { # include $view; # POC : /forum/forumphp?view=Shell # milw0rmcom [2007-09-27] ...