Vulnerabilities > CVE-2007-1416 - Remote File Include vulnerability in Jccorp Urlshrink 1.3.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code via a URL in the formurl parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | JCCorp URLShrink Free 1.3.1 CreateURL.PHP Remote File Include Vulnerability. CVE-2007-1416. Webapps exploit for php platform |
id | EDB-ID:29722 |
last seen | 2016-02-03 |
modified | 2007-03-09 |
published | 2007-03-09 |
reporter | Hasadya Raed |
source | https://www.exploit-db.com/download/29722/ |
title | JCCorp URLShrink Free 1.3.1 CreateURL.PHP Remote File Include Vulnerability |
References
- http://osvdb.org/33982
- http://secunia.com/advisories/24340
- http://securityreason.com/securityalert/2415
- http://www.securityfocus.com/archive/1/462310/100/0/threaded
- http://www.securityfocus.com/archive/1/463523/100/0/threaded
- http://www.securityfocus.com/bid/22894
- http://www.vupen.com/english/advisories/2007/0902