Vulnerabilities > CVE-2007-0167 - Remote File Include vulnerability in PPC Search Engine INC Parameter

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ppc-search-engine
wgs-ppc
exploit available

Summary

Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.

Vulnerable Configurations

Part Description Count
Application
Ppc_Search_Engine
1
Application
Wgs-Ppc
1

Exploit-Db

descriptionPPC Search Engine 1.61 (INC) Multiple Remote File Include Vulnerabilities. CVE-2007-0167. Webapps exploit for php platform
fileexploits/php/webapps/3104.txt
idEDB-ID:3104
last seen2016-01-31
modified2007-01-09
platformphp
port
published2007-01-09
reporterIbnuSina
sourcehttps://www.exploit-db.com/download/3104/
titlePPC Search Engine 1.61 INC Multiple Remote File Include Vulnerabilities
typewebapps