Vulnerabilities > CVE-2007-0301 - Remote File Include vulnerability in Fdweb Espace Membre 2.01

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
fdweb
exploit available

Summary

PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. Successful exploitation requires that "register_globals" is enabled.

Vulnerable Configurations

Part Description Count
Application
Fdweb
2

Exploit-Db

descriptionFdWeB Espace Membre <= 2.01 (path) Remote File Include Exploit. CVE-2007-0301. Webapps exploit for php platform
fileexploits/php/webapps/3123.html
idEDB-ID:3123
last seen2016-01-31
modified2007-01-13
platformphp
port
published2007-01-13
reporterajann
sourcehttps://www.exploit-db.com/download/3123/
titleFdWeB Espace Membre <= 2.01 path Remote File Include Exploit
typewebapps