Vulnerabilities > CVE-2007-1968 - Remote File Include vulnerability in MyBlog Games.PHP

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
sam-crew
exploit available

Summary

PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter.

Exploit-Db

descriptionMyBlog: PHP and MySQL Blog/CMS software RFI Vulnerability. CVE-2007-1968. Webapps exploit for php platform
fileexploits/php/webapps/3685.txt
idEDB-ID:3685
last seen2016-01-31
modified2007-04-08
platformphp
port
published2007-04-08
reporterthe_Edit0r
sourcehttps://www.exploit-db.com/download/3685/
titleMyBlog: PHP and MySQL Blog/CMS software RFI Vulnerability
typewebapps