Lucene search

K
cveMitreCVE-2007-6191
HistoryNov 30, 2007 - 1:46 a.m.

CVE-2007-6191

2007-11-3001:46:00
CWE-94
mitre
web.nvd.nist.gov
24
cve-2007-6191
php
remote file inclusion
armin burger
p.mapper
vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.02

Percentile

89.0%

Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PM_INCPHP] parameter to (1) incphp/globals.php or (2) plugins/export/mc_table.php. NOTE: it could be argued that this vulnerability is caused by a problem in PHP and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in p.mapper.

Affected configurations

Nvd
Node
pmapperp.mapperMatch3.2.0_beta3
VendorProductVersionCPE
pmapperp.mapper3.2.0_beta3cpe:2.3:a:pmapper:p.mapper:3.2.0_beta3:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.02

Percentile

89.0%

Related for CVE-2007-6191