Vulnerabilities > CVE-2007-0300 - Remote File Include vulnerability in TLM CMS Chemin Parameter

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
tlm-cms
exploit available

Summary

PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter. Successful exploitation requires that "register_globals" is enabled.

Vulnerable Configurations

Part Description Count
Application
Tlm_Cms
1

Exploit-Db

descriptionTLM CMS <= 1.1 (i-accueil.php chemin) Remote File Include Vulnerability. CVE-2007-0300. Webapps exploit for php platform
fileexploits/php/webapps/3118.txt
idEDB-ID:3118
last seen2016-01-31
modified2007-01-12
platformphp
port
published2007-01-12
reporterGoLd_M
sourcehttps://www.exploit-db.com/download/3118/
titleTLM CMS <= 1.1 i-accueil.php chemin Remote File Include Vulnerability
typewebapps