Vulnerabilities > CVE-2007-0850 - Local File Include vulnerability in SYSCP System Control Panel Panel_CronScript Table

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
syscp-team

Summary

scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.

Vulnerable Configurations

Part Description Count
Application
Syscp_Team
2