Vulnerabilities > CVE-2007-1525 - Remote PHP Code Execution vulnerability in Dayfox Designs Dayfox Blog 4

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
dayfox-designs
exploit available

Summary

Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.

Vulnerable Configurations

Part Description Count
Application
Dayfox_Designs
1

Exploit-Db

descriptionDayfox Blog 4 (postpost.php) Remote Code Execution Vulnerability. CVE-2007-1525. Webapps exploit for php platform
fileexploits/php/webapps/3478.html
idEDB-ID:3478
last seen2016-01-31
modified2007-03-14
platformphp
port
published2007-03-14
reporterDj7xpl
sourcehttps://www.exploit-db.com/download/3478/
titleDayfox Blog 4 postpost.php Remote Code Execution Vulnerability
typewebapps