Vulnerabilities > CVE-2007-2254 - Unspecified vulnerability in Deltascripts PHP Classifieds 6.04
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04, and probably earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this product was referred to as "Allfaclassfieds" in the original disclosure.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://securityreason.com/securityalert/2618
- http://securityreason.com/securityalert/2618
- http://www.attrition.org/pipermail/vim/2007-April/001543.html
- http://www.attrition.org/pipermail/vim/2007-April/001543.html
- http://www.securityfocus.com/archive/1/466648/100/0/threaded
- http://www.securityfocus.com/archive/1/466648/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33798
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33798