CVE Database
/

CVE-2007-0182

Back to search

CVE-2007-0182

Published: Jan 11, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/. NOTE: the include/common_function.php vector is already covered by another candidate from the same date.

VendorProductVersions

n/a

n/a

affected
n/a

References

33419
vdb-entry
x_refsource_OSVDB
33433
vdb-entry
x_refsource_OSVDB
33436
vdb-entry
x_refsource_OSVDB
33432
vdb-entry
x_refsource_OSVDB
33430
vdb-entry
x_refsource_OSVDB
33439
vdb-entry
x_refsource_OSVDB
33426
vdb-entry
x_refsource_OSVDB
32668
vdb-entry
x_refsource_OSVDB
33413
vdb-entry
x_refsource_OSVDB
33411
vdb-entry
x_refsource_OSVDB
33415
vdb-entry
x_refsource_OSVDB
33420
vdb-entry
x_refsource_OSVDB
33438
vdb-entry
x_refsource_OSVDB
33425
vdb-entry
x_refsource_OSVDB
33418
vdb-entry
x_refsource_OSVDB
33427
vdb-entry
x_refsource_OSVDB
2136
third-party-advisory
x_refsource_SREASON
33434
vdb-entry
x_refsource_OSVDB
33423
vdb-entry
x_refsource_OSVDB
33417
vdb-entry
x_refsource_OSVDB
33412
vdb-entry
x_refsource_OSVDB
33421
vdb-entry
x_refsource_OSVDB
33428
vdb-entry
x_refsource_OSVDB
33422
vdb-entry
x_refsource_OSVDB
21965
vdb-entry
x_refsource_BID
33437
vdb-entry
x_refsource_OSVDB
33414
vdb-entry
x_refsource_OSVDB
33429
vdb-entry
x_refsource_OSVDB
33435
vdb-entry
x_refsource_OSVDB
33431
vdb-entry
x_refsource_OSVDB
33416
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now