Lucene search

K
cveMitreCVE-2007-4120
HistoryAug 01, 2007 - 4:17 p.m.

CVE-2007-4120

2007-08-0116:17:00
mitre
web.nvd.nist.gov
26
cve-2007-4120
php
remote file inclusion
jelsoft vbulletin 3.6.5
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.012

Percentile

85.4%

Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) classfile parameter to includes/functions.php, the (2) nextitem parameter to includes/functions_cron.php, and the (3) specialtemplates parameter to includes/functions_forumdisplay.php. NOTE: this issue is disputed by a reliable third party who states “further investigation has revealed that the application is not vulnerable to this issue.” The original researcher also has a history of erroneous claims

Affected configurations

Nvd
Node
jelsoftvbulletinMatch3.6.5
VendorProductVersionCPE
jelsoftvbulletin3.6.5cpe:2.3:a:jelsoft:vbulletin:3.6.5:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.012

Percentile

85.4%

Related for CVE-2007-4120