Lucene search

K
cveMitreCVE-2007-1986
HistoryApr 12, 2007 - 1:19 a.m.

CVE-2007-1986

2007-04-1201:19:00
mitre
web.nvd.nist.gov
35
cve
php
remote file inclusion
barnraiser
aroundme
vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.131

Percentile

95.6%

Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_path_core parameter to inc/core_profile.header.php, the (2) template_path_core parameter to template/barnraiser_01/maint_contact_view.tpl.php, and the (3) template_path parameter to template/barnraiser_01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.

Affected configurations

Nvd
Node
barnraiseraroundmeMatch0.7.7
VendorProductVersionCPE
barnraiseraroundme0.7.7cpe:2.3:a:barnraiser:aroundme:0.7.7:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.131

Percentile

95.6%