CVE Database
/

CVE-2007-1790

Back to search

CVE-2007-1790

Published: Mar 31, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a URL in the install_root parameter to (1) support.inc.php, (2) function.inc.php, (3) rdal_object.inc.php, (4) rdal_editor.inc.php. (5) login.inc.php, (6) request.inc.php, and (7) categories.inc.php in include/core/; (8) save.inc.php, (9) preview.inc.php, (10) edit_item.inc.php, (11) new_item.inc.php, and (12) item_info.inc.php in include/display/item/; (13) search.inc.php, (14) item_edit.inc.php, (15) register_succsess.inc.php, (16) context_menu.inc.php, (17) item_repost.inc.php, (18) balance.inc.php, (19) featured.inc.php, (20) user.inc.php, (21) buynow.inc.php, (22) install_complete.inc.php, (23) fees_info.inc.php, (24) user_feedback.inc.php, (25) admin_balance.inc.php, (26) activate.inc.php, (27) user_info.inc.php, (28) member.inc.php, (29) add_bid.inc.php, (30) items_filter.inc.php, (31) my_info.inc.php, (32) register.inc.php, (33) leave_feedback.inc.php, and (34) user_auctions.inc.php in include/display/; and (35) design/form.inc.php, (36) processor.inc.php, (37) interfaces.inc.php (38) left_menu.inc.php, (39) login.inc.php, and (40) categories.inc.php in include/.

VendorProductVersions

n/a

n/a

affected
n/a

References

34582
vdb-entry
x_refsource_OSVDB
ADV-2007-1180
vdb-entry
x_refsource_VUPEN
34551
vdb-entry
x_refsource_OSVDB
34548
vdb-entry
x_refsource_OSVDB
34558
vdb-entry
x_refsource_OSVDB
34572
vdb-entry
x_refsource_OSVDB
34578
vdb-entry
x_refsource_OSVDB
34553
vdb-entry
x_refsource_OSVDB
34573
vdb-entry
x_refsource_OSVDB
34584
vdb-entry
x_refsource_OSVDB
34564
vdb-entry
x_refsource_OSVDB
3607
exploit
x_refsource_EXPLOIT-DB
34556
vdb-entry
x_refsource_OSVDB
34575
vdb-entry
x_refsource_OSVDB
34568
vdb-entry
x_refsource_OSVDB
34554
vdb-entry
x_refsource_OSVDB
34563
vdb-entry
x_refsource_OSVDB
34571
vdb-entry
x_refsource_OSVDB
34570
vdb-entry
x_refsource_OSVDB
34560
vdb-entry
x_refsource_OSVDB
34557
vdb-entry
x_refsource_OSVDB
34583
vdb-entry
x_refsource_OSVDB
34547
vdb-entry
x_refsource_OSVDB
34552
vdb-entry
x_refsource_OSVDB
34545
vdb-entry
x_refsource_OSVDB
34561
vdb-entry
x_refsource_OSVDB
34581
vdb-entry
x_refsource_OSVDB
34580
vdb-entry
x_refsource_OSVDB
34567
vdb-entry
x_refsource_OSVDB
34579
vdb-entry
x_refsource_OSVDB
34569
vdb-entry
x_refsource_OSVDB
34559
vdb-entry
x_refsource_OSVDB
34576
vdb-entry
x_refsource_OSVDB
34550
vdb-entry
x_refsource_OSVDB
34577
vdb-entry
x_refsource_OSVDB
24696
third-party-advisory
x_refsource_SECUNIA
34549
vdb-entry
x_refsource_OSVDB
34566
vdb-entry
x_refsource_OSVDB
34574
vdb-entry
x_refsource_OSVDB
34562
vdb-entry
x_refsource_OSVDB
23211
vdb-entry
x_refsource_BID
34565
vdb-entry
x_refsource_OSVDB
34555
vdb-entry
x_refsource_OSVDB
34546
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now