Vulnerabilities > CVE-2007-1421 - Remote File Include vulnerability in Premod Subdog Premod Subdog 2

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
premod-subdog
critical
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in includes/.

Vulnerable Configurations

Part Description Count
Application
Premod_Subdog
1

Exploit-Db

  • descriptionPremod SubDog 2 includes/functions_kb.php phpbb_root_path Parameter Remote File Inclusion. CVE-2007-1421 . Webapps exploit for php platform
    idEDB-ID:29727
    last seen2016-02-03
    modified2007-03-10
    published2007-03-10
    reporterHasadya Raed
    sourcehttps://www.exploit-db.com/download/29727/
    titlePremod SubDog 2 includes/functions_kb.php phpbb_root_path Parameter Remote File Inclusion
  • descriptionPremod SubDog 2 includes/themen_portal_mitte.php phpbb_root_path Parameter Remote File Inclusion. CVE-2007-1421. Webapps exploit for php platform
    idEDB-ID:29728
    last seen2016-02-03
    modified2007-03-10
    published2007-03-10
    reporterHasadya Raed
    sourcehttps://www.exploit-db.com/download/29728/
    titlePremod SubDog 2 includes/themen_portal_mitte.php phpbb_root_path Parameter Remote File Inclusion
  • descriptionPremod SubDog 2 includes/logger_engine.php phpbb_root_path Parameter Remote File Inclusion. CVE-2007-1421. Webapps exploit for php platform
    idEDB-ID:29729
    last seen2016-02-03
    modified2007-03-10
    published2007-03-10
    reporterHasadya Raed
    sourcehttps://www.exploit-db.com/download/29729/
    titlePremod SubDog 2 includes/logger_engine.php phpbb_root_path Parameter Remote File Inclusion