Vulnerabilities > CVE-2007-0900 - Unspecified vulnerability in Tagit Tagboard
Summary
Multiple PHP remote file inclusion vulnerabilities in TagIt! Tagboard 2.1.B Build 2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) configpath parameter to (a) tagviewer.php, (b) tag_process.php, and (c) CONFIG/errmsg.inc.php; and (d) addTagmin.php, (e) ban_watch.php, (f) delTagmin.php, (g) delTag.php, (h) editTagmin.php, (i) editTag.php, (j) manageTagmins.php, and (k) verify.php in tagmin/; the (2) adminpath parameter to (l) tagviewer.php, (m) tag_process.php, and (n) tagmin/index.php; and the (3) admin parameter to (o) readconf.php, (p) updateconf.php, (q) updatefilter.php, and (r) wordfilter.php in tagmin/; different vectors than CVE-2006-5249.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Tagit! Tagit2b 2.1.B Build 2 tagmin/manageTagmins.php configpath Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29587 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29587/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/manageTagmins.php configpath Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/updatefilter.php admin Parameter Remote File Inclusion. CVE-2007-0900 . Webapps exploit for php platform id EDB-ID:29592 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29592/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/updatefilter.php admin Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/index.php adminpath Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29589 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29589/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/index.php adminpath Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tag_process.php Multiple Parameter Remote File Inclusion. CVE-2007-0900 . Webapps exploit for php platform id EDB-ID:29579 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29579/ title Tagit! Tagit2b 2.1.B Build 2 tag_process.php Multiple Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 CONFIG/errmsg.inc.php configpath Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29580 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29580/ title Tagit! Tagit2b 2.1.B Build 2 CONFIG/errmsg.inc.php configpath Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/addTagmin.php configpath Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29581 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29581/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/addTagmin.php configpath Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagviewer.php Multiple Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29578 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29578/ title Tagit! Tagit2b 2.1.B Build 2 tagviewer.php Multiple Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/editTagmin.php configpath Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29585 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29585/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/editTagmin.php configpath Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/verify.php configpath Parameter Remote File Inclusion. CVE-2007-0900 . Webapps exploit for php platform id EDB-ID:29588 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29588/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/verify.php configpath Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/readconf.php admin Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29590 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29590/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/readconf.php admin Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/updateconf.php admin Parameter Remote File Inclusion. CVE-2007-0900 . Webapps exploit for php platform id EDB-ID:29591 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29591/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/updateconf.php admin Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/wordfilter.php admin Parameter Remote File Inclusion. CVE-2007-0900 . Webapps exploit for php platform id EDB-ID:29593 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29593/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/wordfilter.php admin Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/delTagmin.php configpath Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29583 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29583/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/delTagmin.php configpath Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/delTag.php configpath Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29584 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29584/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/delTag.php configpath Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/ban_watch.php configpath Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29582 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29582/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/ban_watch.php configpath Parameter Remote File Inclusion description Tagit! Tagit2b 2.1.B Build 2 tagmin/editTag.php configpath Parameter Remote File Inclusion. CVE-2007-0900. Webapps exploit for php platform id EDB-ID:29586 last seen 2016-02-03 modified 2007-02-12 published 2007-02-12 reporter K-159 source https://www.exploit-db.com/download/29586/ title Tagit! Tagit2b 2.1.B Build 2 tagmin/editTag.php configpath Parameter Remote File Inclusion
References
- http://advisories.echo.or.id/adv/adv65-K-159-2007.txt
- http://advisories.echo.or.id/adv/adv65-K-159-2007.txt
- http://www.osvdb.org/34603
- http://www.osvdb.org/34603
- http://www.osvdb.org/34604
- http://www.osvdb.org/34604
- http://www.osvdb.org/34605
- http://www.osvdb.org/34605
- http://www.osvdb.org/34606
- http://www.osvdb.org/34606
- http://www.osvdb.org/34607
- http://www.osvdb.org/34607
- http://www.osvdb.org/34608
- http://www.osvdb.org/34608
- http://www.osvdb.org/34609
- http://www.osvdb.org/34609
- http://www.osvdb.org/34610
- http://www.osvdb.org/34610
- http://www.osvdb.org/34611
- http://www.osvdb.org/34611
- http://www.osvdb.org/34612
- http://www.osvdb.org/34612
- http://www.osvdb.org/34613
- http://www.osvdb.org/34613
- http://www.osvdb.org/34614
- http://www.osvdb.org/34614
- http://www.osvdb.org/34615
- http://www.osvdb.org/34615
- http://www.osvdb.org/34616
- http://www.osvdb.org/34616
- http://www.osvdb.org/34617
- http://www.osvdb.org/34617
- http://www.osvdb.org/34618
- http://www.osvdb.org/34618
- http://www.securityfocus.com/bid/22518
- http://www.securityfocus.com/bid/22518
- http://www.vupen.com/english/advisories/2007/0557
- http://www.vupen.com/english/advisories/2007/0557
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32436
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32436