Lucene search

K
cve[email protected]CVE-2007-2358
HistoryApr 30, 2007 - 10:19 p.m.

CVE-2007-2358

2007-04-3022:19:00
web.nvd.nist.gov
23
cve
2007
2358
php
remote file
inclusion
b2evolution
arbitrary code
vulnerability
url

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.4%

Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, © admin.php, (d) contact.php, (e) default.php, (f) index.php, and (g) multiblogs.php in blogs/; the (2) view_path and (3) control_path parameters to blogs/admin.php; and the (4) skins_path parameter to (h) blogs/contact.php and (i) blogs/multiblogs.php. NOTE: this issue is disputed by CVE, since the inc_path, view_path, control_path, and skins_path variables are all initialized in conf/_advanced.php before they are used

Affected configurations

NVD
Node
b2evolutionb2evolution
CPENameOperatorVersion
b2evolution:b2evolutionb2evolutioneq*

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.4%

Related for CVE-2007-2358