Lucene search

K
cve[email protected]CVE-2007-2077
HistoryApr 18, 2007 - 3:19 a.m.

CVE-2007-2077

2007-04-1803:19:00
web.nvd.nist.gov
18
php
remote file inclusion
maian search 1.1
vulnerability
security
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%

PHP remote file inclusion vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating “this issue was fixed last year and [no] is longer a problem.”

Affected configurations

NVD
Node
maiansearchMatch1.1
CPENameOperatorVersion
maian:searchmaian searcheq1.1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%

Related for CVE-2007-2077