Vulnerabilities > CVE-2007-1059 - Remote File Include vulnerability in Ultimate FUN Book Ultimate FUN Book 1.02

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ultimate-fun-book
exploit available

Summary

PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the gbpfad parameter. NOTE: some sources mention "Ultimate Fun Board," but this appears to be an error.

Vulnerable Configurations

Part Description Count
Application
Ultimate_Fun_Book
1

Exploit-Db

descriptionUltimate Fun Book 1.02 (function.php) Remote File Include Vulnerability. CVE-2007-1059. Webapps exploit for php platform
fileexploits/php/webapps/3336.txt
idEDB-ID:3336
last seen2016-01-31
modified2007-02-20
platformphp
port
published2007-02-20
reporterkezzap66345
sourcehttps://www.exploit-db.com/download/3336/
titleUltimate Fun Book 1.02 function.php Remote File Include Vulnerability
typewebapps