Vulnerabilities > CVE-2007-0496 - Remote Security vulnerability in Neon Labs Website

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
neon-labs
critical
exploit available

Summary

PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.

Vulnerable Configurations

Part Description Count
Application
Neon_Labs
1

Exploit-Db

descriptionNeon Labs Website <= 3.2 (nl.php g_strRootDir) Remote Inclusion Vuln. CVE-2007-0496. Webapps exploit for php platform
fileexploits/php/webapps/3163.txt
idEDB-ID:3163
last seen2016-01-31
modified2007-01-20
platformphp
port
published2007-01-20
reporter3l3ctric-Cracker
sourcehttps://www.exploit-db.com/download/3163/
titleNeon Labs Website <= 3.2 nl.php g_strRootDir Remote Inclusion Vuln
typewebapps