6.8
CVSSv2

CVE-2007-6147

Published: 27/11/2007 Updated: 19/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote malicious users to execute arbitrary PHP code via a URL in the (a) php_root_path and sometimes the (b) privilege_root_path parameter to various PHP scripts under (1) admin/includes/, (2) admin/phase/, (3) includes/, (4) includes/page_includes/, (5) reviewer/includes/, (6) reviewer/phase/, and (7) user/phase/.

Vulnerable Product Search on Vulmon Subscribe to Product

iaprcommence iapr commence 1.3

Exploits

~~~~~~~~~~~~~~~~~~~~~~~~ ~ iaprcommence 13 RFI ~ ~~~~~~~~~~~~~~~~~~~~~~~ --------------------- Author : ShAy6oOoN --------------------- Group : PitBull Crew --------------------- Script : iaprcommence 13 --------------------- Download : downloadssourceforgenet/iaprcommence/CommenceV1_3 ...