Lucene search

K
cve[email protected]CVE-2007-1631
HistoryMar 23, 2007 - 9:19 p.m.

CVE-2007-1631

2007-03-2321:19:00
web.nvd.nist.gov
27
cve-2007-1631
php
remote file inclusion
clbox 1.01
signup.php
security vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.5%

PHP remote file inclusion vulnerability in signup.php in CLBOX 1.01 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: this issue has been disputed by a reliable third party, stating that header is defined through an include file before use

Affected configurations

NVD
Node
clboxclboxMatch1.01
CPENameOperatorVersion
clbox:clboxclboxeq1.01

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.5%

Related for CVE-2007-1631