CVE Database
/

CVE-2007-1415

Back to search

CVE-2007-1415

Published: Mar 12, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

35115
vdb-entry
x_refsource_OSVDB
35111
vdb-entry
x_refsource_OSVDB
35116
vdb-entry
x_refsource_OSVDB
35101
vdb-entry
x_refsource_OSVDB
35105
vdb-entry
x_refsource_OSVDB
35123
vdb-entry
x_refsource_OSVDB
35121
vdb-entry
x_refsource_OSVDB
35103
vdb-entry
x_refsource_OSVDB
35107
vdb-entry
x_refsource_OSVDB
35106
vdb-entry
x_refsource_OSVDB
3443
exploit
x_refsource_EXPLOIT-DB
35125
vdb-entry
x_refsource_OSVDB
35117
vdb-entry
x_refsource_OSVDB
35112
vdb-entry
x_refsource_OSVDB
35120
vdb-entry
x_refsource_OSVDB
35124
vdb-entry
x_refsource_OSVDB
35110
vdb-entry
x_refsource_OSVDB
35108
vdb-entry
x_refsource_OSVDB
35114
vdb-entry
x_refsource_OSVDB
35119
vdb-entry
x_refsource_OSVDB
22895
vdb-entry
x_refsource_BID
ADV-2007-0917
vdb-entry
x_refsource_VUPEN
35113
vdb-entry
x_refsource_OSVDB
35118
vdb-entry
x_refsource_OSVDB
35102
vdb-entry
x_refsource_OSVDB
35104
vdb-entry
x_refsource_OSVDB
35122
vdb-entry
x_refsource_OSVDB
35109
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now