CVE Database
/

CVE-2007-0167

Back to search

CVE-2007-0167

Published: Jan 10, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.

VendorProductVersions

n/a

n/a

affected
n/a

References

3104
exploit
x_refsource_EXPLOIT-DB
33449
vdb-entry
x_refsource_OSVDB
33445
vdb-entry
x_refsource_OSVDB
2134
third-party-advisory
x_refsource_SREASON
33447
vdb-entry
x_refsource_OSVDB
33454
vdb-entry
x_refsource_OSVDB
21961
vdb-entry
x_refsource_BID
20070109 ppc engine Multiple file inclusion
mailing-list
x_refsource_BUGTRAQ
20070109 "ppc engine" is WGS-PPC
mailing-list
x_refsource_VIM
33450
vdb-entry
x_refsource_OSVDB
33444
vdb-entry
x_refsource_OSVDB
33448
vdb-entry
x_refsource_OSVDB
demoppc-inc-file-include(31355)
vdb-entry
x_refsource_XF
33451
vdb-entry
x_refsource_OSVDB
33452
vdb-entry
x_refsource_OSVDB
33446
vdb-entry
x_refsource_OSVDB
33453
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now