CVE Database
/

CVE-2007-2677

Back to search

CVE-2007-2677

Published: May 14, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the config parameter to includes/language.php, or the Root_Path parameter to (2) layout_admin_cfg.php, (3) layout_cfg.php, or (4) layout_t_top.php in skins/phpchess/. NOTE: vector 1 has been disputed by CVE, since the code is defined within a function that is not called from within includes/language.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

35593
vdb-entry
x_refsource_OSVDB
35595
vdb-entry
x_refsource_OSVDB
23797
vdb-entry
x_refsource_BID
35594
vdb-entry
x_refsource_OSVDB
35592
vdb-entry
x_refsource_OSVDB
ADV-2007-1649
vdb-entry
x_refsource_VUPEN
3837
exploit
x_refsource_EXPLOIT-DB
25147
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now