Vulnerabilities > CVE-2007-0867 - Remote File Include vulnerability in Site-Assistant Menu.PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
site-assistant
exploit available

Summary

PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter.

Vulnerable Configurations

Part Description Count
Application
Site-Assistant
1

Exploit-Db

descriptionSite-Assistant. CVE-2007-0867. Webapps exploit for php platform
fileexploits/php/webapps/3285.html
idEDB-ID:3285
last seen2016-01-31
modified2007-02-08
platformphp
port
published2007-02-08
reporterajann
sourcehttps://www.exploit-db.com/download/3285/
titleSite-Assistant <= 0990 - pathsversion Remote File Include Exploit
typewebapps