Vulnerabilities > CVE-2007-1032 - Remote Security vulnerability in phpMyFAQ

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
phpmyfaq
nessus

Summary

Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server." Successful exploitation requires that "register_globals" is enabled.

Vulnerable Configurations

Part Description Count
Application
Phpmyfaq
108

Nessus

NASL familyCGI abuses
NASL idPHPMYFAQ_1_610.NASL
descriptionThe installation of phpMyFAQ on the remote host allows for bypassing authentication or escalating privileges via the
last seen2020-06-01
modified2020-06-02
plugin id24672
published2007-02-20
reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/24672
titlephpMyFAQ < 1.6.10 Multiple Script Arbitrary File Upload