CVE Database
/

CVE-2007-5146

Back to search

CVE-2007-5146

Published: Oct 1, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in dedi-group Der Dirigent 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the dedi_path parameter to (1) inc.generate_code.php, (2) fnc.type_forms.php, or (3) fnc.type.php in backend/inc/, or (4) frontend.php or (5) backend.php in projekt01/cms/inc/; or (6) the this_dir parameter to backend/inc/class.filemanager.php. NOTE: vectors 4 and 5 are disputed by CVE because PHP encounters a fatal function-call error on a direct request for the file, before reaching the include statement.

VendorProductVersions

n/a

n/a

affected
n/a

References

45536
vdb-entry
x_refsource_OSVDB
45538
vdb-entry
x_refsource_OSVDB
45540
vdb-entry
x_refsource_OSVDB
45539
vdb-entry
x_refsource_OSVDB
45537
vdb-entry
x_refsource_OSVDB
45535
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now