CVE Database
/

CVE-2007-5641

Back to search

CVE-2007-5641

Published: Oct 23, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the full_path parameter to (1) certinfo/index.php, (2) emails/index.php, (3) events/index.php, (4) fax/index.php, (5) files/index.php, (6) files/list.php, (7) groupadm/index.php, (8) history/index.php, (9) info/index.php, (10) log/index.php, (11) mail/index.php, (12) messages/index.php, (13) organizations/index.php, (14) phones/index.php, (15) presence/index.php, (16) projects/index.php, (17) projects/summary.inc.php, (18) projects/list.php, (19) reports/index.php, (20) search/index.php, (21) snf/index.php, (22) syslog/index.php, (23) tasks/searchsimilar.php, (24) tasks/index.php, (25) tasks/summary.inc.php, and (26) useradm/index.php in modules; (27) /ajax/loadsplash.php; (28) /blocks/birthday.php; (29) /blocks/events.php; and (30) /blocks/help.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

41914
vdb-entry
x_refsource_OSVDB
41907
vdb-entry
x_refsource_OSVDB
4549
exploit
x_refsource_EXPLOIT-DB
41917
vdb-entry
x_refsource_OSVDB
41910
vdb-entry
x_refsource_OSVDB
41906
vdb-entry
x_refsource_OSVDB
41957
vdb-entry
x_refsource_OSVDB
41905
vdb-entry
x_refsource_OSVDB
41920
vdb-entry
x_refsource_OSVDB
41975
vdb-entry
x_refsource_OSVDB
41908
vdb-entry
x_refsource_OSVDB
41931
vdb-entry
x_refsource_OSVDB
41918
vdb-entry
x_refsource_OSVDB
41925
vdb-entry
x_refsource_OSVDB
41934
vdb-entry
x_refsource_OSVDB
41927
vdb-entry
x_refsource_OSVDB
26150
vdb-entry
x_refsource_BID
41909
vdb-entry
x_refsource_OSVDB
41928
vdb-entry
x_refsource_OSVDB
41912
vdb-entry
x_refsource_OSVDB
27347
third-party-advisory
x_refsource_SECUNIA
41913
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now