Vulnerabilities > CVE-2007-1219 - Remote File Include vulnerability in Admin Phorum Admin Phorum 3.3.1A

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
admin-phorum
exploit available

Summary

PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

Vulnerable Configurations

Part Description Count
Application
Admin_Phorum
1

Exploit-Db

descriptionAdmin Phorum 3.3.1a (del.php include_path) RFI Vulnerability. CVE-2007-1219. Webapps exploit for php platform
fileexploits/php/webapps/3382.txt
idEDB-ID:3382
last seen2016-01-31
modified2007-02-27
platformphp
port
published2007-02-27
reporterGoLd_M
sourcehttps://www.exploit-db.com/download/3382/
titleAdmin Phorum 3.3.1a del.php include_path RFI Vulnerability
typewebapps