Vulnerabilities > CVE-2004-1554 - Remote PHP File Include vulnerability in Alexphpteam Alex Guestbook 3.12
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | @lexPHPTeam @lex Guestbook 3.12 Remote PHP File Include Vulnerability. CVE-2004-1554. Webapps exploit for php platform |
id | EDB-ID:24638 |
last seen | 2016-02-02 |
modified | 2004-09-27 |
published | 2004-09-27 |
reporter | Himeur Nourredine |
source | https://www.exploit-db.com/download/24638/ |
title | @lexPHPTeam @lex Guestbook 3.12 - Remote PHP File Include Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | ATLEX_GUESTBOOK_FILE_INCLUDE.NASL |
description | The remote host seems to be running @lex guestbook, a guestbook web application written in PHP. The reported version may permit remote attackers, without prior authentication, to include and execute malicious PHP scripts. By modifying the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14830 |
published | 2004-09-27 |
reporter | This script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/14830 |
title | @lex Guestbook livre_include.php chem_absolu Parameter Remote File Inclusion |
code |
|