CVE Database
/

CVE-2007-4525

Back to search

CVE-2007-4525

Published: Aug 25, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelette_cache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelette_cache variable is initialized before use, and is only used within the scope of a function

VendorProductVersions

n/a

n/a

affected
n/a

References

25416
vdb-entry
x_refsource_BID
3056
third-party-advisory
x_refsource_SREASON
20070823 SPIP v1.7 Remote File Inclusion Bug
mailing-list
x_refsource_BUGTRAQ
spip-inccalcul-file-include(36218)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now