Vulnerabilities > CVE-2003-1148 - Remote File Include vulnerability in LES Visiteurs LES Visiteurs 2.0.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
les-visiteurs
nessus
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.

Vulnerable Configurations

Part Description Count
Application
Les_Visiteurs
1

Exploit-Db

descriptionLes Visiteurs 2.0 Remote File Include. CVE-2003-1148. Webapps exploit for php platform
idEDB-ID:23302
last seen2016-02-02
modified2003-10-27
published2003-10-27
reporterMatthieu Peschaud
sourcehttps://www.exploit-db.com/download/23302/
titleLes Visiteurs 2.0 - Remote File Include

Nessus

NASL familyCGI abuses
NASL idLES_VISITEURS.NASL
descriptionThe remote
last seen2020-06-01
modified2020-06-02
plugin id11911
published2003-10-27
reporterThis script is Copyright (C) 2003-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/11911
titleLes Visiteurs Multiple Remote File Inclusion