Lucene search

K
cveMitreCVE-2007-4950
HistorySep 18, 2007 - 8:17 p.m.

CVE-2007-4950

2007-09-1820:17:00
CWE-94
mitre
web.nvd.nist.gov
27
cve
php
remote file inclusion
vulnerability
phportal

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.01

Percentile

84.1%

PHP remote file inclusion vulnerability in form/db_form/employee.php in PHPortal 0.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: this issue is disputed by CVE, since DOCUMENT_ROOT cannot be modified by an attacker

Affected configurations

Nvd
Node
phportalphportalMatch0.2.7
VendorProductVersionCPE
phportalphportal0.2.7cpe:2.3:a:phportal:phportal:0.2.7:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.01

Percentile

84.1%

Related for CVE-2007-4950