Lucene search

K
cve[email protected]CVE-2007-5168
HistoryOct 01, 2007 - 5:17 a.m.

CVE-2007-5168

2007-10-0105:17:00
CWE-20
web.nvd.nist.gov
22
cve-2007-5168
php
remote file inclusion
clanlite
security vulnerability
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

79.0%

Multiple PHP remote file inclusion vulnerabilities in ClanLite 1.23.01.2005 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) modules/serveur_jeux.php or (2) conf/conf-php.php. NOTE: vector 1 is disputed by CVE because the require_once is only reached when a certain constant has already been defined.

Affected configurations

NVD
Node
clanliteclanliteMatch1.23.01.2005

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

79.0%

Related for CVE-2007-5168