7.5

CVE-2007-0050

Exploit
PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter.  NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenpinboardOpenpinboard Version2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.48% 0.705
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2007-01/0176.html
http://osvdb.org/33375
http://www.securityfocus.com/archive/1/455795/100/0/threaded
http://www.securityfocus.com/archive/1/455818/100/0/threaded
Vendor Advisory
Exploit