Vulnerabilities > CVE-2007-1809 - Remote File Include vulnerability in Grafx Software Company Website Builder 1.5

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
grafx-software
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than CVE-2007-1513.

Vulnerable Configurations

Part Description Count
Application
Grafx_Software
1

Exploit-Db

descriptionCWB PRO 1.5 (INCLUDE_PATH) Remote File Inclusion Vulnerabilities. CVE-2007-1809. Webapps exploit for php platform
fileexploits/php/webapps/3628.txt
idEDB-ID:3628
last seen2016-01-31
modified2007-04-01
platformphp
port
published2007-04-01
reporterGoLd_M
sourcehttps://www.exploit-db.com/download/3628/
titleCWB PRO 1.5 INCLUDE_PATH Remote File Inclusion Vulnerabilities
typewebapps