Vulnerabilities > CVE-2007-1837 - Remote File Include vulnerability in Mangobery CMS Mangobery CMS 0.5.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_Path parameter to (1) boxes/quotes.php or (2) templates/mangobery/footer.sample.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | MangoBery CMS 0.5.5 (quotes.php) Remote File Inclusion Vulnerability. CVE-2007-1837. Webapps exploit for php platform |
file | exploits/php/webapps/3598.txt |
id | EDB-ID:3598 |
last seen | 2016-01-31 |
modified | 2007-03-28 |
platform | php |
port | |
published | 2007-03-28 |
reporter | kezzap66345 |
source | https://www.exploit-db.com/download/3598/ |
title | MangoBery CMS 0.5.5 quotes.php Remote File Inclusion Vulnerability |
type | webapps |
References
- http://mangobery.svn.sourceforge.net/viewvc/mangobery?view=rev&revision=70
- http://osvdb.org/34509
- http://osvdb.org/34510
- http://secunia.com/advisories/24686
- http://www.securityfocus.com/bid/23187
- http://www.vupen.com/english/advisories/2007/1147
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33290
- https://www.exploit-db.com/exploits/3598