Lucene search

K
cveMitreCVE-2007-0854
HistoryFeb 08, 2007 - 6:28 p.m.

CVE-2007-0854

2007-02-0818:28:00
CWE-94
mitre
web.nvd.nist.gov
29
cpanel
whm
remote file inclusion
vulnerability
remote code execution
url
cve-2007-0854
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.045

Percentile

92.5%

Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitrary code via a URL in the obj parameter. NOTE: a third party claims that this issue is not file inclusion because the contents are not parsed, but the attack can be used to overwrite files in /var/cpanel/objcache or provide unexpected web page contents.

Affected configurations

Nvd
Node
cpanelwebhost_manager
VendorProductVersionCPE
cpanelwebhost_manager*cpe:2.3:a:cpanel:webhost_manager:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.045

Percentile

92.5%

Related for CVE-2007-0854