Vulnerabilities > CVE-2007-2182 - Unspecified vulnerability in Maran PHP Forum

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
maran
exploit available

Summary

Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.

Vulnerable Configurations

Part Description Count
Application
Maran
1

Exploit-Db

descriptionMaran PHP Forum (forum_write.php) Remote Code Execution Vulnerability. CVE-2007-2182. Webapps exploit for php platform
fileexploits/php/webapps/3775.txt
idEDB-ID:3775
last seen2016-01-31
modified2007-04-22
platformphp
port
published2007-04-22
reporterDj7xpl
sourcehttps://www.exploit-db.com/download/3775/
titleMaran PHP Forum forum_write.php Remote Code Execution Vulnerability
typewebapps