Vulnerabilities > CVE-2007-2156 - Remote File Include vulnerability in Rezervi Root Parameter

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
rezervi-generic
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) datumVonDatumBis.inc.php, (2) footer.inc.php, (3) header.inc.php, and (4) stylesheets.php in templates/; and (5) wochenuebersicht.inc.php, (6) monatsuebersicht.inc.php, (7) jahresuebersicht.inc.php, and (8) tagesuebersicht.inc.php in belegungsplan/.

Vulnerable Configurations

Part Description Count
Application
Rezervi_Generic
1

Exploit-Db

descriptionRezervi 0.9 (root) Remote File Inclusion Vulnerabilities. CVE-2007-2156. Webapps exploit for php platform
fileexploits/php/webapps/3763.txt
idEDB-ID:3763
last seen2016-01-31
modified2007-04-18
platformphp
port
published2007-04-18
reporterGoLd_M
sourcehttps://www.exploit-db.com/download/3763/
titleRezervi 0.9 root Remote File Inclusion Vulnerabilities
typewebapps