Vulnerabilities > CVE-2007-0182 - Remote File Include vulnerability in Magic Photo Storage Website

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
scriptaty
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/. NOTE: the include/common_function.php vector is already covered by another candidate from the same date.

Vulnerable Configurations

Part Description Count
Application
Scriptaty
1

Exploit-Db

  • descriptionMagic Photo Storage Website user/change_catalog_template.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182 . Webapps exploit for php plat...
    idEDB-ID:29422
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29422/
    titleMagic Photo Storage Website - user/change_catalog_template.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/add_templates.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182 . Webapps exploit for php platform
    idEDB-ID:29410
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29410/
    titleMagic Photo Storage Website - admin/add_templates.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/user_email.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29432
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29432/
    titleMagic Photo Storage Website - user/user_email.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/approve_member.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29412
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29412/
    titleMagic Photo Storage Website - admin/approve_member.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/index.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29414
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29414/
    titleMagic Photo Storage Website - admin/index.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/delete_category.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29425
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29425/
    titleMagic Photo Storage Website - user/delete_category.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/index.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29426
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29426/
    titleMagic Photo Storage Website - user/index.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/admin_password.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29407
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29407/
    titleMagic Photo Storage Website - admin/admin_password.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/delete_member.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29413
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29413/
    titleMagic Photo Storage Website - admin/delete_member.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/login.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29427
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29427/
    titleMagic Photo Storage Website - user/login.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/list_members.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29415
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29415/
    titleMagic Photo Storage Website - admin/list_members.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/send_email.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29417
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29417/
    titleMagic Photo Storage Website - admin/send_email.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website include/db_config.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29419
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29419/
    titleMagic Photo Storage Website - include/db_config.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/add_news.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29421
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29421/
    titleMagic Photo Storage Website - user/add_news.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/couple_milestone.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29423
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29423/
    titleMagic Photo Storage Website - user/couple_milestone.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/user_membership_password.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php plat...
    idEDB-ID:29434
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29434/
    titleMagic Photo Storage Website - user/user_membership_password.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/logout.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182 . Webapps exploit for php platform
    idEDB-ID:29428
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29428/
    titleMagic Photo Storage Website - user/logout.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/admin_paypal_email.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182 . Webapps exploit for php platform
    idEDB-ID:29411
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29411/
    titleMagic Photo Storage Website - admin/admin_paypal_email.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/couple_profile.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29424
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29424/
    titleMagic Photo Storage Website - user/couple_profile.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/user_catelog_password.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29431
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29431/
    titleMagic Photo Storage Website - user/user_catelog_password.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website include/config.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182 . Webapps exploit for php platform
    idEDB-ID:29418
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29418/
    titleMagic Photo Storage Website - include/config.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/register.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182 . Webapps exploit for php platform
    idEDB-ID:29429
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29429/
    titleMagic Photo Storage Website - user/register.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/user_extend.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182 . Webapps exploit for php platform
    idEDB-ID:29433
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29433/
    titleMagic Photo Storage Website - user/user_extend.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website user/upload_photo.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182 . Webapps exploit for php platform
    idEDB-ID:29430
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29430/
    titleMagic Photo Storage Website - user/upload_photo.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/admin_email.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29409
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29409/
    titleMagic Photo Storage Website - admin/admin_email.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/add_welcome_text.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182. Webapps exploit for php platform
    idEDB-ID:29408
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29408/
    titleMagic Photo Storage Website - admin/add_welcome_text.php _configsite_path Parameter Remote File Inclusion
  • descriptionMagic Photo Storage Website admin/membership_pricing.php _config[site_path] Parameter Remote File Inclusion. CVE-2007-0182 . Webapps exploit for php platform
    idEDB-ID:29416
    last seen2016-02-03
    modified2007-01-09
    published2007-01-09
    reporterIbnuSina
    sourcehttps://www.exploit-db.com/download/29416/
    titleMagic Photo Storage Website - admin/membership_pricing.php _configsite_path Parameter Remote File Inclusion