Vulnerabilities > CVE-2007-1423 - Remote File Include vulnerability in Work System ECommerce Include_Top.PHP

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
work-system-e-commerce
critical
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts. Successful exploitation requires that "register_globals" is enabled.

Exploit-Db

descriptionWORK system e-commerce <= 3.0.5 Remote File Inclusion Vulnerability. CVE-2007-1423. Webapps exploit for php platform
fileexploits/php/webapps/3448.txt
idEDB-ID:3448
last seen2016-01-31
modified2007-03-10
platformphp
port
published2007-03-10
reporterRodrigo Duarte
sourcehttps://www.exploit-db.com/download/3448/
titlework system e-commerce <= 3.0.5 - Remote File Inclusion Vulnerability
typewebapps